Re: Delegating permission to add computers to the domain
From: Jon Paskett (paskettj_at_email.NOSPAM.com)
Date: 03/27/04
- Previous message: Stivie S.: "RE: _Msdcs.domain.com Zone Creation"
- In reply to: David Everett [MSFT]: "Re: Delegating permission to add computers to the domain"
- Next in thread: Jon Paskett: "Re: Delegating permission to add computers to the domain"
- Reply: Jon Paskett: "Re: Delegating permission to add computers to the domain"
- Reply: Ulf B. Simon-Weidner [MVP]: "Re: Delegating permission to add computers to the domain"
- Messages sorted by: [ date ] [ thread ]
Date: Sat, 27 Mar 2004 12:41:40 -0500
Thanks for the reply David,
You are focusing on the Computers container. I understand that default
behavior is that new computers are created in the Computers container. Can
this be changed, based upon group membership, to automatically add them to a
Computers OU located within their Parent? That is my ultimate goal. They can
predeploy them, but I want to have the ability to automatically add them to
the OU they are delegated permission to do so.
Thanks for your help
Jon
"David Everett [MSFT]" <deverett@online.microsoft.com> wrote in message
news:u%23MaYN3EEHA.4080@TK2MSFTNGP09.phx.gbl...
> One minor change to Step 7....
>
> Instead of Editing the Existing rights, Add the user or group again to the
> Advanced Security and click "Apply onto...". In the drop-down box select
> Computer Objects and then set Allow on the following:
> a. Read all Properties
> b. Write all Properties
> c. Change Password
> d. Reset Password
>
> In the end they will have "Create Computer Objects" and "Delete Computer
> Objects" on "This object and all child objects" and the 4 rights listed
> above on "Computer Objects".
> --
> David Everett
> Microsoft Corporation
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> "Jon Paskett" <paskettj@email.NOSPAM.com> wrote in message
> news:up#ExIqEEHA.1544@TK2MSFTNGP11.phx.gbl...
> > OS = Windows Server 2003
> >
> > I need to delegate permission to a group of users to add computers to
the
> > domain in their OU only. Creating a custom task allowing Object Type =
> > Computer Objects, Create/Delete objects with Full Control Permission in
> the
> > custom delegation wizard. However, this does not allow group members to
> add
> > the computer to the domain. AD says user does not have permission.
> >
> > TIA
> >
> > Jon
> >
> >
>
>
- Previous message: Stivie S.: "RE: _Msdcs.domain.com Zone Creation"
- In reply to: David Everett [MSFT]: "Re: Delegating permission to add computers to the domain"
- Next in thread: Jon Paskett: "Re: Delegating permission to add computers to the domain"
- Reply: Jon Paskett: "Re: Delegating permission to add computers to the domain"
- Reply: Ulf B. Simon-Weidner [MVP]: "Re: Delegating permission to add computers to the domain"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|