replication monitoring rights

From: edwardb (dirwolf_at_speakeasy.net)
Date: 01/26/05


Date: Wed, 26 Jan 2005 12:47:17 -0500

We have recently gone through a strict security measure and removed
pretty much everyone from domain admins and started to delegate every
little task people need to do.
There are 2 things I have questions about:
1. What rights are needed to perform AD replication monitoring when not
a domain admin?
2. Using vbscript and the adsi interface, performing mass updates to
user account. I have a feeling that .setinfo cannot be done as they are
not longer domain admins, BUT, have full delegation to their users? Is
there another permission needed for this?

Thanks.



Relevant Pages

  • Re: Remove Domain Admins ability from "Delegation Of Control"
    ... Domain Admins and administrators are very powerfull groups. ... There is no point of having a group that would only be able to delegate all ... Then i plan on removing the the Read Members, ... > modify the restricted group membership to this "restricted group ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegate Authority
    ... Domain Admins is protected from delegatation with the adminsdholder functionality, you can move that group into any OU you want and the delegation in that OU will not allow someone to modify the group. ... I want to delegate certain roles to the HD folks by putting them in group named 'SupportAdmins' or something similar. ... I do NOT want the group inside the Organization OU as then have the ability to kick eachother out of the group or attempt to add the SupportAdmins groups to the Domain Admins group again correct? ...
    (microsoft.public.win2000.security)
  • Re: Different Sites - One Database ?
    ... Create one site and delegate the necessary permissions to the different ... permissions to the child sites to the respective domain admins. ... MVP SMS ...
    (microsoft.public.sms.setup)
  • Re: Delegation of Authority in an OU
    ... Delegate Administrative Authority in Windows 2000. ... > The steps outlined here will also work within Windows Server 2003. ... > delegated permissions does NOT need to be a member of the Domain Admins ... > group or any similar administrative group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Incoming E-Mail - cant create contact in OU
    ... configure Email Enabled Lists in Moss2007 RTM using Exchange 2007" at ... I have WSS website application pool running as a domain user account, ... However to prove its a permission issue, ... application pool account to domain admins, rebooted my WSS to be sure and ...
    (microsoft.public.sharepoint.windowsservices)