Re: Delegation of groups admin. - restricted to a subset of objects



the original poster states:

"only add a certain set of computers as members to a set of groups"

this is not possible!

why?

if you are delegated the right to manage group membership, you are delegated
the right to make EVERY SECURITY PRINCIPAL (users,groups,computers) a member
of that group

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* How to ask a question --> http://support.microsoft.com/?id=555375
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Dragos CAMARA" <dragos_c@xxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:681B128E-7350-4731-A99F-5300694A8D9B@xxxxxxxxxxxxxxxx
i do like this :
place the main application group in other OU,
create a application group in each OU so the administrators can add the
computers to that group, and add this applications groups to the main
application group.
--
Dragos CAMARA
MCSA Windows 2003 server


"Gaute" wrote:

We have delegated administraion of computer objects (workstations) for
specific OUs. So if you are a workstation admin in one OU you can only
manage
the workstations in this OU and not other OUs (Full control).

We are now creating application groups where workstations are to be
members. The application groups are common for all in the domain.

We want to delegate administration of the application groups (to
add/remove
members of the application group) to the workstation admins. We can
create a
separate delegated group for this. But the delegated administrator of the
application group should only be able to add and remove workstations
which
are within the OU where he has delegated rights, not other workstations
in
the domain. Workstations within an OU are in addition member of separate
groups.

Is this possible within AD or do we need a web solution? Any suggestions?

Thanks

Gaute



.



Relevant Pages

  • Re: adding workstations to a Win2k domain
    ... > workstation accounts to the domain. ... You only need to delegate the ... there is a built in limit of 10 computers that anyone can add to ... The Add workstations to domain user right ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to give permissions
    ... For adding computers to domain, you can give specific users permission "add ... called e.g. "Permissions to add workstations to the domain". ... group "add workstations to the domain" permissions on Default Domain ... For resetting accounts and passwords delegate these permissions to another ...
    (microsoft.public.windows.server.general)
  • Re: Burkes International REegister of Arms
    ... The senior line does not demand any fee; aside from 100 euros to cover the ... The junior line Order does require its members ... charity and has not published accounts detailing how these funds ... The Delegate of this Order in 2004 on an Irish radio programme ...
    (rec.heraldry)
  • Re: Administrators Group in Local Users and Groups
    ... I had it set up right, it just took a while to get out to the workstations. ... > right click on restricted groups and select new group (For the local ... this group name should be - administrators) and key in the ... Select add on the Members of this group and then ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changes for Next Years Pennsic
    ... simply because most of the members shirk them. ... share) is of the opinion that cooperatives never last long as ... about how humans delegate certain tasks to some of their members, ... how humans get things done. ...
    (rec.org.sca)