Re: restrict delegated admins to create computer accounts in AD
From: ptwilliams (ptw2001_at_hotmail.com)
Date: 09/25/04
- Next message: ptwilliams: "Re: username limitation"
- Previous message: ptwilliams: "Re: ad replication"
- In reply to: umut cavusoglu: "restrict delegated admins to create computer accounts in AD"
- Next in thread: umut cavusoglu: "Re: restrict delegated admins to create computer accounts in AD"
- Reply: umut cavusoglu: "Re: restrict delegated admins to create computer accounts in AD"
- Messages sorted by: [ date ] [ thread ]
Date: Sat, 25 Sep 2004 12:14:30 +0100
The way to do this is to create security groups (domain local) and give
those groups an advanced write permission(s) to the OUs they represent, e.g.
OU=UK, Domain Local Security Group = ouUK, and then add users to a global
group and add that group to the domain local.
Now, any users added to the global groups that are members of the
appropriate local groups will be able to prestage computer accounts in their
OUs. These computers can then be joined to the domain and will be members
of the appropriate OU -as the computer will recognise it's prestaged
account.
The exact permissions required are:
-- Create Computer Objects
-- Delete Computer Objects
To access these permissions, use the advanced DACL editor on the OU you wish
to make this change on.
These permissions can also be set through the delegation of control wizard.
Paul Williams
_______________________________
http://www.msresource.net
Join us in our free, public forum:
http://forums.msresource.net
_______________________________
"umut cavusoglu" <umutcavusoglu@discussions.microsoft.com> wrote in message
news:69E246B2-80F8-4066-8258-BB5680E9FAAF@microsoft.com...
i need help to restrict my sub-admins those distributed across different
locations to create or to pre-stage limited computer accounts -not add
computers to domain- in AD hierarchy?
- Next message: ptwilliams: "Re: username limitation"
- Previous message: ptwilliams: "Re: ad replication"
- In reply to: umut cavusoglu: "restrict delegated admins to create computer accounts in AD"
- Next in thread: umut cavusoglu: "Re: restrict delegated admins to create computer accounts in AD"
- Reply: umut cavusoglu: "Re: restrict delegated admins to create computer accounts in AD"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|