Re: Server Logon

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 07/03/04

  • Next message: Julien: "Problem when installing Win2K & IEv6.0 through the GPO's"
    Date: Sat, 03 Jul 2004 22:45:49 GMT
    
    

    You can use delegation and group membership. Members of the local power
    users/administrators groups can do most of what you want on a server [other than
    domain controller] . Users can be delegated the right to add workstations to the
    domain via delegation which gives them the permission to create computer objects.
    However I think only domain administrators can install software on domain controllers
    and there is good reason for that as only trusted and knowledgeable users should have
    access to domain controllers. The user right for logon locally and deny logon locally
    in the appropriate security policy [domain/local/OU] can be used to control what
    computers a user can logon to as can their account properties in their domain AD
    account with the "logon to" option. Be very careful with deny permissions as
    administrators are also members of users and everyone group. The links below may
    help. --- Steve

    http://www.microsoft.com/technet/security/topics/issues/w2kccscg/w2kscgcd.mspx
    http://www.microsoft.com/resources/documentation/windows/2000/server/reskit/en-us/distsys/part5/dsgappd.mspx

    "Shamim" <anonymous@discussions.microsoft.com> wrote in message
    news:259ee01c460c5$2f9f4f50$a401280a@phx.gbl...
    > Dear Friends.
    > i want to give sharing rights to some users so that they
    > can share some folders on the network.I also want them to
    > to give them some adminsitrative rights of installing the
    > software,Printers and Join a workstation to the Domain,
    > but at the same time i want to restrict thier logon to my
    > Windows 2000 Domain Controllers.Can i set these
    > permissions through Delegation Wizard or Group Policy.
    >
    > I will appericate your help
    >
    > Cheers
    > Shamim.


  • Next message: Julien: "Problem when installing Win2K & IEv6.0 through the GPO's"

    Relevant Pages

    • Re: Constrained delegation question!
      ... remote server running the services in terms of the security audits on the ... AUTHORITY\ANONYMOUS LOGON event. ... you won't be able to get Kerb delegation to ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: About a dozen U.S. lawmakers in Israel
      ... Close to a dozen members of both houses of Congress were in Israel ... traveling on his own; a four-person delegation ... senior member of the House Intelligence Committee, ...
      (alt.politics.bush)
    • Re: WMI in ASP fails on 2003 (err 80041003); works fine on 2000
      ... > Strike the comment about the interactive logon. ... I still don't see the need for delegation. ... >>> tested it on two servers with no problems. ... >>> interactive logon - thus WMI to remote machine should be a single hop) ...
      (microsoft.public.win32.programmer.wmi)
    • Re: Cannot find global policies Red X in place of it.
      ... If the domain controller is not trusted for delegation that is a problem. ... Edit the Default Domain Controllers Policy and go to Computer ... >>> In an effort to resolve a problem with NTFRS ID:Event ... >>> domain policies I have a big re XXX. ...
      (microsoft.public.win2000.active_directory)
    • Re: Calling NetUserGetInfo from ASP.NET app
      ... I am using Integrated Windows Authentication, ... you wouldn't need delegation to work. ... I also enabled logon auditing in the local ... Co-author of "The .NET Developer's Guide to Directory Services ...
      (microsoft.public.dotnet.framework.aspnet.security)