Re: domain rights without being in Domain Users group

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



You don't need to be in Domain Users. You can grant or deny access to any
group (although if you're in 2k mixed mode you can't use domain local groups
on members). The problem you face though is that Authenticated Users has a
whole bunch of read access throughout the domain itself. However, if you're
concerned from a file and folder perspective (as the apps to view the domain
are locked down), then by all means simply grant necessary access to a group
that this object is a member of.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



.



Relevant Pages

  • Re: Prevent Users interactive login, but allow them to run batch j
    ... That user is member of "Domain Users" group. ... on Locally) But the second setting "Log on as batch job" has no effect. ... but that the account needs something else. ... Domain Users as well as Authenticated Users are made members ...
    (microsoft.public.win2000.security)
  • Re: users have gray hair in Domain Users group
    ... The members of domain users group in both of the tree domains have ... when I use the below script to enumerate the membership of the ... domain users group in each of the domains, ... any reasons why I cannot enumerate the Domain Local group? ...
    (microsoft.public.win2000.active_directory)
  • Re: simple distribution lists?
    ... list members change, someone has to go into ADUC and add/delete/reconfigure, ... > However, if you want to internal users send email to a distribution list, ... > the persons in the list are unnecessary to be domain users or contacts. ... Open outlook. ...
    (microsoft.public.windows.server.sbs)
  • Re: Can this be done without affecting current configuration
    ... group so it only belong to the nondomainuser group. ... is able to access the shared folder without problem. ... the members in the domain users group which is something I don't want. ...
    (microsoft.public.windows.server.security)
  • Re: Prevent Users interactive login, but allow them to run batch j
    ... needed for this account to run the job without being an admin. ... on Locally) But the second setting "Log on as batch job" has no ... Domain Users as well as Authenticated Users are made members ...
    (microsoft.public.win2000.security)