Re: Delegate permission to full control OU (GPO):getting access is denied. Server Operator can do it.

From: Tim Springston [MS] (tspring_at_online.microsoft.com)
Date: 08/29/04


Date: Sun, 29 Aug 2004 13:18:12 -0500

That would certainly do it as well. Since there are two components to group
policies (the AD one and the file systen one in the SYSVOL share) the user
must have allow permissions to both for that action.

-- 
Tim Springston
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"Marlon Brown" <marlon_brownj@hotmail.com> wrote in message 
news:ekadRsliEHA.704@TK2MSFTNGP09.phx.gbl...
> Found the problem:
> Compared \sysvol with a clean Win2000 setup and it seems somebody removed
> GrouPolicy Creator owner from the \sysvol share.
> "Marlon Brown" <marlon_brown@hotmail.com> wrote in message
> news:e00pcpeiEHA.596@TK2MSFTNGP11.phx.gbl...
>> Yes, the permissions below are checked for MyAdmin, but he is still
> getting
>> the 'access is denied' message.
>> I created a copy account named TestMyadmin (domain user only and member 
>> of
>> ControlOU group, which has full-control over that OU) and the problem
>> persists. Any other suggestions ?
>>
>> "Tim Springston [MS]" <tspring@online.microsoft.com> wrote in message
>> news:O32mW%23aiEHA.2448@TK2MSFTNGP12.phx.gbl...
>> > Hi Marlon-
>> >
>> > This could be dependant on other security group memberships which that
>> user
>> > is a member of, however, the granular permission that the user should
> need
>> > is "Create groupPolicyContainer objects" and "Delete
> groupPolicyContainer
>> > objects".
>> >
>> > This is viewable from Active Directory Users and Computers (DSA.MSC),
>> from
>> > the properties of the OU->Security folder tab->Advanced.
>> >
>> > Please repost if adding that user to have those Allow permissions does
> not
>> > help.
>> >
>> > -- 
>> > Tim Springston
>> > Microsoft Corporation
>> > This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>> >
>> >
>> > "Marlon Brown" <marlon_brownj@hotmail.com> wrote in message
>> > news:%23ve0CdZiEHA.2764@TK2MSFTNGP11.phx.gbl...
>> > >I go to a CertainOU and I attempt to give Myadmin ability to full
> control
>> > > that one, including create GPOs.
>> > > MyAdmin is member of Group Policy Creator Owner.
>> > >
>> > > When Myadmin right click the OU and attemp to create "new" to create 
>> > > a
>> new
>> > > group policy, he is getting message 'You do not have permission to
>> perform
>> > > this operation - access is denied'.
>> > >
>> > > What's wrong ?
>> > >
>> > > If I add the fellow to the "Server Operators" group he is able to
>> > > accomplish
>> > > the task just fine. I am unsure if he is successfull because the
> Server
>> > > Operator has read+execute permissions to Sysvol ? I see that
>> Authenticated
>> > > user also has r+x to Sysvol and therefore that doesn't explain...
>> > >
>> > >
>> > >
>> >
>> >
>>
>>
>
> 


Relevant Pages

  • Re: Delegate permission to full control OU (GPO):getting access is denied. Server Operator can do it
    ... Yes, the permissions below are checked for MyAdmin, but he is still getting ... ControlOU group, which has full-control over that OU) and the problem ... > is a member of, however, the granular permission that the user should need ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegate permission to full control OU (GPO):getting access is denied. Server Operator can do it
    ... > ControlOU group, which has full-control over that OU) and the problem ... >> is a member of, however, the granular permission that the user should ... >> Please repost if adding that user to have those Allow permissions does ...
    (microsoft.public.win2000.active_directory)
  • Re: Changing groups
    ... pleaderb, sue, frank, ed are members of group projectb ... Everyone is a member of group user. ... depending on the file's permissions they can read and write the ... I do this all the time, using Samba. ...
    (Debian-User)
  • Re: Outside Users RDP into WS2008???
    ... Name it DL-Consultants ... Assign permissions on a resource to domain local group '. ... add any user account belonging to your consultants to become member of G-Consultants group. ... End disconnected session: ...
    (microsoft.public.windows.server.general)
  • Re: How to remove a user from a mail group (Tried to search...)
    ... If you're using Distribution Groups, these cannot show up in any ACLs ... If it is a Security Group, you'll need to figure out the what different ... resources the group could have permissions on. ... I go to "member of" tab. ...
    (microsoft.public.exchange.admin)