Re: delegating administrative access

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 02/28/05


Date: Mon, 28 Feb 2005 21:08:50 -0000

The user also needs administrative permissions and rights on the source
computer.

So, the junior admins needs the create and delete computer object permission
on the OU that the computer is in, and needs to be a member of the local
administrators group on the PC that is being renamed.

-- 
Paul Williams
http://www.msresource.net
http://forums.msresource.net
"richierich" <rsr2564@hotmail.com> wrote in message 
news:OxClw1cHFHA.1392@TK2MSFTNGP10.phx.gbl...
No, your direction is not correct.  The question is, what permissions are
needed to rename a computer object in AD?  I too thought add/del would work,
but it stil gives an access denied when attempting to rename a computer
already in AD.
-thanks
"ptwilliams" <ptw2001@hotmail.com.donotspam> wrote in message
news:DC5BBF86-CA90-46EE-BA2A-A10BF1E81CA2@microsoft.com...
> That's it.  Although he'll also need read, but should have that by
> default.
>
> What isn't working if you've done this?  What error are you getting?
>
> Start by checking that the DHCP Client Service is rset to automatically
> start
> and is running on the DC; that the DNS zone accepts dynamic updates; and
> that
> the DC is pointing to itself for DNS.
>
> Once you've done this, restart netlogon.
>
> After restarting netlogon, run netdiag /test:dns.
>
> Run the tests again.
>
> The missing SPNs is worrying; however, we have to make sure DNS is working
> correctly before we can further troubleshoot anything else...
>
> --
>
> Paul Williams
>
> http://www.msresource.net/
> http://forums.msresource.net/
>
> "richierich" wrote:
>
>> funny, I did that and it did not work.  I thought that would be it too.
>> mmmmm.   anything else to look at?
>>
>>
>> "ptwilliams" <ptw2001@hotmail.com.donotspam> wrote in message
>> news:0B7B022D-B104-44EC-A40B-8552CFE55971@microsoft.com...
>> > Load ADU&C (dsa.msc) and select Advanced Features from the View
>> > drop-down
>> > menu.
>> >
>> > Then right-click the container or OU that you wish to configure the
>> > delegation on and choose properties.  In the properties tab, choose
>> > Security
>> > and then Advanced.  In the Access Control Settings for <OU Name> choose
>> > add,
>> > add the user name, and then in the Permission Entry for <OU Name>
>> > select
>> > the
>> > following Allow permissions:
>> >
>> > Create Computer Objects
>> > Delete Computer Objects
>> >
>> >
>> > Hope this helps,
>> >
>> > --
>> >
>> > Paul Williams
>> >
>> > http://www.msresource.net/
>> > http://forums.msresource.net/
>> >
>> > "richierich" wrote:
>> >
>> >> I want to delegate admin tasks to a jr admin.  I want him specifically
>> >> to
>> >> be
>> >> able to rename computer objects in my domsin.  what settings do I need
>> >> to
>> >> check to allow this?  I did the delegation wizard, but it is not that
>> >> granular in its use.
>> >>
>> >> -thanks
>> >>
>> >>
>> >>
>>
>>
>>


Relevant Pages

  • Re: What happens to the machine name in AD?
    ... The user needs Write permissions on the computer object to modify all ... usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Trying to use NetJoinDomain API...
    ... Nope I used the delegation wizard to set ACLs, and I also went in and added ... These are the permissions granted to the group, ... Computer Objects ...
    (microsoft.public.windows.server.active_directory)
  • Re: What happens to the machine name in AD?
    ... The normal user doesn't have these permissions, ... > usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Allow users to change Description attribute for computer account
    ... by giving a users group create computer objects permission on the domain or ... The delegation wizard simply changes AD permissions on the object. ... > I found a script on technet from the scripting guys. ...
    (microsoft.public.security)
  • Re: DSACLS and joining a domain
    ... What really happens with this user right is the DACL check is ignored when ... > Create computer objects is an special permission in Active Directory that> you will see on a container such as the domain container or an> Organizational Unit in advanced page when you add a group to or edit> permissions for a group. ... The user right for add workstations to the domain> will only allow a user to add ten workstations to the domain by default. ...
    (microsoft.public.win2000.security)