RSOP Planning Security problem

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I've been trying to do some RSOP Planning using a non-admin user account on
a domain member workstation.
I am using the following VBScript code:

strComputer = "DC1"
Set locator = CreateObject("WbemScripting.SWbemLocator")
Set connection = locator.ConnectServer (strComputer, "root\rsop", null,
null, null, null, 0, null)
(for the ConnectServer parameters, see
http://msdn.microsoft.com/en-us/library/aa393720(VS.85).aspx)

When I logon to the workstation as an administrator - no problem executing
the script.
When I use a non-admin account, I get an error 80070005 access denied
message executing line 3.

I have used the wmimgmt.msc mmc to set permissions on Root\RSOP for
"Authenticated Users" to the same as "Administrators" for "this namespace
and subnamespaces".

I have also granted "Authenticated Users" permission for "RSOP Planning" and
"RSOP Logging" on the OU which contains the workstation account.

What permissions am I missing???


.



Relevant Pages

  • Re: Trust relationship between this workstation and Primary Domain
    ... it, with a new computer ID, a new workgroup ID, but again to no avail. ... password policy, renamed admin account, automatic updates are controlled by ... * PLEASE post all messages and replies in the newsgroups ... "Workstation ...
    (microsoft.public.win2000.networking)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... account is NEW to the workstation. ... needs admin group priv at workstation level. ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... The DNS Zone for your AD Domain must be DYNAMIC, ... Client computer must use STRICTLY the INTERNAL DNS server which can ...
    (microsoft.public.windows.server.active_directory)
  • Joining NT4 to a Windows 2000 domain; secure channel prob?
    ... Trying to logon with a domain account pops up the error: ... The trust relationship between this workstation and the primary ... Searching PDC for domain MYDOMAIN ... ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re-Post - "the trust relationship between this workstation and
    ... There were no logged events in either the DC or workstation. ... DC/DNS Server - DCDiag ... Attr: subschemaSubentry ... only problem is adding a new user account on the station. ...
    (microsoft.public.windows.server.active_directory)