RE: Delegated permission to add computers

From: ptwilliams (ptw2001_at_hotmail.com.donotspam)
Date: 01/10/05


Date: Mon, 10 Jan 2005 08:15:05 -0800

What permissions have you set, and with what scope?

I'd say you want this:

Allow - groupName - Create/ Delete Computer Objects - This object and all
child objects
Allow - groupName - Full Control - Computer Objects

You can also delegate this using the wizard; you just need to add computer
objects as a custom delegation task.

There's also a property on the domain that allows any user to join up to 10
machines to the domain. You might want to change this. Search google for
ms-DS-MachineAccountQuota. This is the property that controls this.

--
Paul Williams
http://www.msresource.net/
http://forums.msresource.net/
"Jeff" wrote:
> I created a group in AD and delegated permission for that group to add 
> computers to the default computer container.  For some reason when a user in 
> the group attempts to add a PC to the domain (via My COmputer | Properties), 
> it returns an access denied error.  What can I do to troubleshoot this? 
> Everything looks correct in AD? Am I missing a permission somewhere?
> 
> Thanks,
> 
> Jeff 
> 
> 
> 


Relevant Pages

  • Re: Delegating Control...
    ... Reset user passwords ... domain user has permission to join 10 clients into domain. ... You may want to delegate user/group create, list, view permission to the ... You may want to delegate users/groups full control permission to the groups ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegating Control...
    ... | Thread-Topic: Delegating Control... ... Reset user passwords ... domain user has permission to join 10 clients into domain. ... |> You may want to delegate user/group create, list, view permission to ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegated permission to add computers
    ... Computers container, I get an access denied message when I try to add the ... Jeff ... > You can also delegate this using the wizard; you just need to add computer ... Am I missing a permission somewhere? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forcing Ownership of files
    ... >> without that right IF they have Full Control. ... > have explicit permission to do whatever they like with the content of ... > when I first tuned up here from a Novell server to a Windows 2000 server ... Now they are worried about security so ...
    (microsoft.public.win2000.active_directory)
  • Re: PM Security Issue
    ... gives me permission to open projects in Microsoft Project Professional. ... Categories control what you can do it to. ... in which I am a team member, and in which my resources are team members. ... When the My Projects category is included in the Project Managers group, ...
    (microsoft.public.project.pro_and_server)