Re: Computer Objects

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 02/13/05


Date: Sat, 12 Feb 2005 19:18:00 -0500

In a nutshell, if you want to move items in the DS from one container to
another, you need three permissions:
1) DELETE on the object being moved or DELETE_CHILD on the source container
2) WRITE_PROP on the object being moved for RDN and CN.
3) CREATE_CHILD on the target container

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Mark Clark wrote:
> Hello
> I am trying to find the correct permission to delegate the authority to MOVE 
> computer objects within ADUC. It is obvious that the permission to create and 
> delete computer objects is available per OU, but I would also like delegate 
> the authority to move computer objects within AD without giving too many 
> rights. 
> 
> Additionally, is it possible to change the default location for created 
> computer accounts within AD? Can this change be made within AD?
> 
> Thank you very much for your assistance,
> 
> Mark Clark 


Relevant Pages

  • Re: Computer Objects
    ... With the permission to move comes the question, ... > I am trying to find the correct permission to delegate the authority to ... > delete computer objects is available per OU, ... > the authority to move computer objects within AD without giving too many ...
    (microsoft.public.win2000.active_directory)
  • Re: Exchange 2007 installation error
    ... Given, however, what I saw in terms of permission changes to the container ... ports on the Exchange Server before it is deployed again..... ... I had no problems installing it at that time. ...
    (microsoft.public.exchange.setup)
  • Re: Joining computers to the domain
    ... You could delegate permissions on the Computers container, so that your delegates can create and delete computer objects in there. ... Right now, when they add computers to the domain, the computer account is ...
    (microsoft.public.windows.server.active_directory)
  • Re: CryptAcquireContext fails with error 6 (The handle is invalid)
    ... You can check/change the permissions on a key container with the ... | From: "Phil Ten" ... | I applied the suggested permissions and it did not help. ... | How could I check the actual permission applied ...
    (microsoft.public.platformsdk.security)
  • Re: Delegated permission to add computers
    ... This setup was initially done using the delegated control wizard. ... Right now the group has the following permission: ... I am going to try to add Full Control permissions on computer objects to see ... Jeff ...
    (microsoft.public.windows.server.active_directory)