Re: ADACLS inheritance option

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Ulf,

Good point! Many people overlook that.

--
Cary W. Shultz
Roanoke, VA 24012

"Ulf B. Simon-Weidner [MVP]" <nospam2-ulf@xxxxxxxxxxxxxxxxxx> wrote in
message news:OyCO3i2gGHA.3628@xxxxxxxxxxxxxxxxxxxxxxx
-----Original Message-----
From: Khalil N. Z. [mailto:KhalilNZ@xxxxxxxxxxxxxxxxxxxxxxxxx]
Posted At: Monday, May 29, 2006 11:34 PM
Posted To: microsoft.public.windows.server.active_directory
Conversation: ADACLS inheritance option
Subject: ADACLS inheritance option

Hi all,

I´m creating a script using adacls.exe to grant permissions
for a group to move computers and I´m granting permissions on
the root of the AD.

My question is when I use the option /I:T the permission that
will be propagated is all the permissions on the root or only
the new one?

I´m executing a command like this:

dsacls "DC=Domain,DC=Com" /G Domain\Group:CC;computer


Hello Khalil,

If you use /I:T and apply it onto the domainhead (dc=domain,dc=com) the
group will have the right to create computer accounts everywhere in the
domain (each OU, Container and sub-OU).

I'd recommend using the same command, but apply it only to
cn=computers,dc=domain,dc=com and/or any other OU you want them to be able
to create computer accounts.

Gruesse - Sincerely,

Ulf B. Simon-Weidner

Profile & Publications:
http://mvp.support.microsoft.com/profile=35E388DE-4885-4308-B489-F2F1214C811D
Weblog: http://msmvps.org/UlfBSimonWeidner
Website: http://www.windowsserverfaq.org


.



Relevant Pages

  • =?utf-8?B?cmU6IEFEQUNMUyBpbmhlcml0YW5jZSBvcHRpb24=?=
    ... Website: http://www.windowsserverfaq.org ... Conversation: ADACLS inheritance option ... but I need to grant permissions for a spesific ... the group will have the right to create computer accounts everywhere ...
    (microsoft.public.windows.server.active_directory)
  • Re: join domain/create computer accounts... driving me NUTS!
    ... the RIGHT way to do this is to simply give "create/delete computer object" ... Then give full control permissions to ... > one group that pre-creates computer accounts in the correct OU ... > one group that pre-creates computer accounts in the correct OU and joins ...
    (microsoft.public.windows.server.active_directory)
  • Re: restrict delegated admins to create computer accounts in AD
    ... If you wish these people a maximum number of machines to be added, ... no more than 50 computer accounts with DACL settings allowed??? ... "ptwilliams" wrote:> The way to do this is to create security groups and give> those groups an advanced write permissionto the OUs they represent, ... > The exact permissions required are:> -- Create Computer Objects ...
    (microsoft.public.windows.server.active_directory)
  • Re: Deploying Software with Computer GPO Errors
    ... Computers to both the share and folder permissions as well as the individual ... computer accounts for the two PC's I am testing. ... the package set to advanced. ... >> Now If I do the samer thing via a User Install it seems to work fine. ...
    (microsoft.public.win2000.active_directory)
  • Re: restrict delegated admins to create computer accounts in AD
    ... The way to do this is to create security groups and give ... appropriate local groups will be able to prestage computer accounts in their ... -- Create Computer Objects ... To access these permissions, use the advanced DACL editor on the OU you wish ...
    (microsoft.public.windows.server.active_directory)