Re: Resetting the ms-DS-MachineAccountQuota attribute for a single use

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Method 3: Override the Default Limit of the Number of Computers an
Authenticated User Can Join to a Domain
You can override the default limit, using either of the following methods: .
Use the Ldp (Ldp.exe) tool included in the Microsoft Windows 2000 Resource
Kit.
. Use an Active Directory Services Interface (ADSI) script to increase
or decrease the value of the Active Directory ms-DS-MachineAccountQuota
attribute. To do this: 1. Install the Windows 2000 Support tools if they
have not already been installed. To install these tools, run Setup.exe from
the Support\Tools folder on the Windows 2000 Server or the Windows 2000
Professional CD-ROM.
2. Run Adsiedit.msc as an administrator of the domain.
3. Expand the Domain NC node. This node contains an object that
begins with "DC=" and reflects the correct domain name. Right-click this
object, and then click Properties.
4. In the Select which properties to view box, click Both.
5. In the Select a property to view box, click
ms-DS-MachineAccountQuota.
6. In the Edit Attribute box, type a number. This number
represents the number of workstations that you want users to be able to
maintain concurrently.
Click Set, and then click OK.



Increase the amount defined in step 6

It would be much simpler though to Delegate the user in question the
ability to create machine accounts in the specfic OU. Just start the
Delegate Wizard select the user and grant them create user machine accounts.

Here is a start for you.
http://searchwindowssecurity.techtarget.com/generic/0,295582,sid45_gci1050014,00.html

I highly recommend the Delegation and discourage the Override limit.
The limit impacts all users in your domain. The Delegation is user specific
and you can control who can create what. As a matter of fact best practice
would be to grant a Global Group the delegation and then place the user you
want to create within this group. That way as people change positions it is
as simple as removing or adding users to this group to provide the
permissions they need with out you having to change the permissions.




--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"Kruse" <Kruse@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7C683138-55F5-43DB-9BC2-0959C45EE562@xxxxxxxxxxxxxxxx
In KB251335, Microsoft states that it is possible to reset the limit, when
an
user has exceeded the maximum number of computer accounts he is allowed to
create in this domain. But how do I do this.


.



Relevant Pages

  • Re: Propagating caller identity across applications from a bare ASMX Service method to a WSE3 Servic
    ... Directory Domain as the server computer and the server App Pool run-as ... Windows 2003 Server mode -- they may be in Windows 2000 mixed mode. ... to be configured so as to use kerberos delegation. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: "Account is trusted for delegation" is not shown
    ... Where SPN is the servicename/computername (MESSENGER/SERVERNAME for ... This will add the delegation tab to the useraccount you specified. ... account with the Setspn utility in the support tools on your CD. ... It should be caused by raising functional level to windows 2003. ...
    (microsoft.public.windows.server.general)
  • Re: kerberos sudenly stop working on an IIS server
    ... D_DebugLogClient %wZ sent AS request with no server name\n") ... Windows XP and Windows Server 2003 will recover from this automatically. ... For information about setting up service accounts for delegation, ...
    (microsoft.public.windows.server.active_directory)
  • RE: accessing WebService from asp.net App on load balanced Servers
    ... for intranet application within a windows domain ... For general info on ASP.NET delegation: ... Servers ... | | Subject: RE: accessing WebService from asp.net App on load balanced ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Given access to edit active directory
    ... And if we're mentioning third party tools to help with this, ... DSRAZOR for Windows. ... Once you get the delegation part using the built-in ...
    (microsoft.public.windows.server.active_directory)