Re: Group permissions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Only administrators group members on the sharing-out machine
can access its administrative shares. You should define shares
with the share-level permissions set appropriately and with the
share-root restricted to only the needed. If you non-admin users
have a problem with such share access, tie them together for them
in a DFS struct

"Rob" <Rob@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DC7A0B08-4F90-46D3-8B40-8C9EFB4F82EB@xxxxxxxxxxxxxxxx
I figured out the Remote Desktop problem. Now I just need help on the
administrative share problem.

"Rob" wrote:

We have an IT department of 12 people. We don't want all of them to be
domain
admins, so we created a global security group so that they can remote
into
pc's and the like. Our DC's are currently running Windows 2000. We're
upgrading to 2003 in about a month.
We did delegation of control, created custom task to delegate, delegate
control of this folder (for the OU we selected), checked all 3 boxes for
showing permissions, granted full control. We also created a GPO to allow
logon through terminal services and allow logon locally. We applied the
GPO.
Here are 2 problems we're running into.
1. Members of new global security group cannot remote desktop in to any
machine.
2. Members of new group cannot browse to any administrative share.
Both of the above are critical to these members but for security reasons
we
don't want them to be domain admins.
Any ideas/suggestions?


.



Relevant Pages

  • Re: I CALL BULL SHIT ON MIKE PAYNES "UPA Members Call to Action" artical.....
    ... The stategy should be to get general info from a larger ... members giving feedback no one knows ANYTHING about what the majority ... upa administrators just fine. ... dosent it seem odd to you that upa administrators have never seen fit ...
    (rec.sport.disc)
  • Re: [Full-Disclosure] UTTER HORSESHIT: [was January 15 is Personal Firewall Day, help the cause]
    ... > ever heard for not using security products. ... Many of the people on here care nothing about security, ... >> If Annie's weren't members of Administrators, ... >> Administrators would not have access to apps like IE and OE, ...
    (Full-Disclosure)
  • Re: Help needed setting up roaming administrator
    ... >Administrators group (just type in Administrators, don't browse for it, ... >add your Roaming Local Admins group to the Members of this group section ... GPO associated with the OU that contains the computers I want to use ... restricted group and to define the groups the restricted group will ...
    (microsoft.public.win2000.security)
  • Re: Domain Users to have Local Admin rights
    ... members inside the Restricted Group, but it still doesn't wanna work. ... all machines that are with scope of the GPO carrying the Restricted ... their local Administrators group. ... group you define a Restricted Group definition, ...
    (microsoft.public.windows.server.security)
  • Re: Accessing another computers administrative shares
    ... administrative shares), is valuable or not. ... And as far as I know, some API can be used as an object in ASP. ... This ASP page is for the Administrators who want to ... >> the all the coming and going files on the users' computers. ...
    (microsoft.public.inetserver.asp.general)