Re: Add the Adminsitrators security group to roaming user profiles

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Do you know if we can just somehow replace the administrators group with
another security group? It has to be somewhere within the servers registry,
right?

"Herb Martin" wrote:

> "S3" <S3@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:1D3D4F28-868F-413D-B521-EC079AA5655D@xxxxxxxxxxxxxxxx
> > Can we somehow just create and ADM file for this.
>
> Yes, but an ADM isn't necessary -- NTFS permissions are already an item
> in GPOs (Computer->WindowsSettings->SecuritySettings->FileSettings.
>
> BUT be warned that this is not a trivial task unless you already are very
> comfortable with permissions (e.g., write batch files to manage them),
> and you might find that setting up a "prototype system", exporting, and
> using (importing) a Security Template (.inf) is easier for you.
>
> > I want to give a security
> > group access to our roaming profiles via a gp. Is it possible?
>
> Yes. But since roaming profiles are on a file server (somewhere) why not
> just set the permissions directly or through a batch file.
>
> This would be a more interesting GPO problem if you had to do this on
> dozens or even thousands of machines.
>
> > I know this
> > canned GPO setting gives the Administrators group access to the profile.
>
> How do you know that? I don't know it.
>
> Such permisssions default to the file systems on the Roaming Profile
> file server(s).
>
> What precisely are you really trying to do? And why is that your goal?
>
> That is, what is your TRUE goal underneath all of this...?
>
> > I
> > was just thinking if we knew where in the registry the Administrators
> group
> > is specified we could just change it to reflect the name/SID of the
> security
> > group that I want to give access to the profiles for.
>
> It isn't -- and that is a different question than you have been asking.
>
> And you don't (normally) want to REMOVE the admins group from such
> access but perhaps ADD another group.
>
> --
> Herb Martin, MCSE, MVP
> Accelerated MCSE
> http://www.LearnQuick.Com
> [phone number on web site]
>
> > "Herb Martin" wrote:
> >
> > > "S3" <S3@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> > > news:E779EEA8-5EBE-48F5-A646-A8F216AF9652@xxxxxxxxxxxxxxxx
> > > > I know we can use the Add the Adminsitrators security group to roaming
> > > user
> > > > profiles setting to give the Admins full access to profiles. My
> questions
> > > is
> > > > how can I substitute the Admnistrators security group for another
> security
> > > > group. Is this value stored on the server registry somewhere? Can we
> > > create
> > > > an ADM template for this. Thanks!!
> > >
> > > Yes.
> > >
> > > But what are you REALLY trying to accomplish? (Rather than
> > > how you think you might do that....)
> > >
> > > SubInAcl.exe (reskit) will change an ACL to reference a different
> > > group.
> > >
> > > --
> > > Herb Martin, MCSE, MVP
> > > Accelerated MCSE
> > > http://www.LearnQuick.Com
> > > [phone number on web site]
> > >
> > >
> > >
>
>
>
.



Relevant Pages

  • Re: Add the Adminsitrators security group to roaming user profiles
    ... > I want to be able to give a certain security group access to user profiles ... > if we can just find where in the registry the administrators group is ... What access will this group actually exercise on Profiles? ... >>> group access to our roaming profiles via a gp. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions or Policy
    ... services are installed and use the Security Templates ... Microsoft MVP (Windows Security) ... > "Herb Martin" wrote in message ... >> you may distribute it to may machine by using a policy. ...
    (microsoft.public.win2000.security)
  • Re: Built-in Administrators group losing members
    ... > Check your group policy settings for a Security Settings\Restricted Group ... > entry set for your administrators group. ... This could be overriding your ...
    (microsoft.public.win2000.active_directory)
  • Re: Newbie question re: security principles
    ... A domain user cannot add accounts to the administrators group (otherwise, ... security would be useless). ... You'll need to log into a domain controller or a ... The you will be able to add your own user account to the ...
    (microsoft.public.win2000.active_directory)
  • Re: Take file ownership.
    ... Microsoft MVP (Windows Server System: Security) ... > Administrators group, and then click OK. ... > The administrator or the Administrators group now owns ...
    (microsoft.public.windowsxp.security_admin)