Weird Permissions Problem

From: Dave Clark (dave.clark_at_ddess.org)
Date: 06/03/04


Date: Thu, 3 Jun 2004 07:57:09 -0700

When logging into a DOMAIN CONTROLLER as what we refer to
as an "OU ADMINISTRATOR" (i.e. does not have DOMAIN ADMIN
rights). All my AD permissions work properly while in AD
Users and Computers. They can only do what we have given
them rights to. However, with AD Users and Computers
running on a WORKSTATION they can do much, much more.

Example in one container we created a OU ADMIN
container. Here at the server logged in as an ou admin
they cannot make any changes to any of the users in this
OU. This is correct.

However, logged in as the same user on a workstation
(which has ADMIN rights to the local workstation), they
can adjust those objects.

WHY are the permissions not working properly apparently?
What am I missing that having AD users and computers on a
local workstation allows changes, but logging into a
domain controller does not and works properly.

I can't for the life of me see where they are getting any
permissions to do this. They are only in 2 groups, and
neither of those groups have any permissions to these
objects.



Relevant Pages

  • Re: Message Tracking Permissions in Exchange 2000
    ... Granting the View Only Admin right is the ... >>rights only to his local site was able to track a message across sites ... >>Administrative permissions on Site B also. ... >>be able to track messages as they flow into any site in the org. ...
    (microsoft.public.exchange.admin)
  • Re: No security tab on a shared printer
    ... I have Admin rights and installed the printer. ... and it tells me to use the Security Tab to change the ... permissions that come along with the Admin account. ...
    (microsoft.public.security)
  • Re: No security tab on a shared printer
    ... > I have Admin rights and installed the printer. ... > and it tells me to use the Security Tab to change the ... > permissions that come along with the Admin account. ...
    (microsoft.public.security)
  • Re: Giving admins Local Admin to DCs not Domain Admins
    ... out permissions over the whole domain. ... Althought I can give the users PowerUser or LocalLogon rights via ... Can you with Server 2003 give a user just local admin to a DC ... but there's no such thing as local administrators ...
    (microsoft.public.security)
  • Re: User Rights In Active Directory
    ... Regular domain users should not have any ability to do any modifying with AD ... unless you have delegated them authority for such via AD permissions to the ... To see what user rights that a user/group has to domain ... rights are defined for the domain controller container. ...
    (microsoft.public.security)