Re: Access Denied - Trusting Computer for Delegation To Services - SORTED



OK got this sorted!

I tried with the default domain admin, which is usually disabled (we don't
use the default domain admin account, instead we made a copy of it, called
something non administrative looking, then disabled the default admin
account, so people can't guess the account by looking for SID 500), and it
worked, I was able to delegate cifs & HOST to the web server.

Strangely, after trying with the default admin account, I tried again with
the replacement admin account and it worked!

Thanks for the help

Ben

"Ben" <benb@xxxxxxxxxxxxxxxx> wrote in message
news:eCGOAYLOIHA.5264@xxxxxxxxxxxxxxxxxxxxxxx
Hi Joe,

Thanks for your reply.

This is the problem, the account I'm using IS domain admin, as well as
Enterprise Admin AND Schema Admin!So I can't understand why it won't let
me set this delegation. I've even added the account to the 'Enable
computer and user accounts to be trusted for delegation' user right on the
default domain policy.

Any ideas?

Ben

"Joe Kaplan" <joseph.e.kaplan@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:%23c9ehpFOIHA.1184@xxxxxxxxxxxxxxxxxxxxxxx
I think you need to be a domain admin to set this flag on a user or
computer account. You can't delegate this locally. I think your domain
admins could potentially delegate this right to other users.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services
Programming"
http://www.directoryprogramming.net
--
"Ben" <benb@xxxxxxxxxxxxxxxx> wrote in message
news:eo6MqhCOIHA.6108@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I've setup some virtual directories in an IIS6 web site, which I would
like our users to be able to access externally. Having read the
following article:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/webapp/iis/remstorg.mspx, I
am trying to setup delegation on the web server via active directory,
however, I have run into an error when performing the delegation steps
to assign the webserver 'trust this computer for delegation to specified
services only'. When I add the services, CIFS & HOST from the file
server, then click apply, I get an error: "The following Active
Directory error occurred: Access is denied".

Having googled around I found a post that said I had to add the 'Enable
computer and user accounts to be trusted for delegation' user right to
the default domain controller policy (Computer configuration > Windows
Settings
Security Settings > Local Policies > User Rights Management > Enable
computer and user accounts to be trusted for delegation), which I did.
However, even after running a GPUPDATE /FORCE on the domain controller I
still get the above error.

Does anyone know how to fix this error?

Many thanks

Ben








.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... central admin pool different than the web app. ... that account a little (if the web app is compromised or something, ... So I started with giving the app pool account domain admins permissions then ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Security Breach in AD! Help!
    ... > about 5 minutes the user was removed from the built in admin group. ... > changed the default domain policy, the default domain controller policy, ... >> auditing of account logon for success and failure and account management ... >> success and failure in Domain Controller Security Policy. ...
    (microsoft.public.win2000.security)
  • Re: cant verify disk
    ... She went to DU, and when she pressed "verify disk", it asked her user ... Disk Utility has required an administrator name and password for certain ... This is clearly a task which requires admin privileges, ... seriously mucked up with her user account settings in the NetInfo ...
    (comp.sys.mac.system)
  • Re: Wscript within VBA
    ... One box is running VBA code,. ... One box is a domain controller, or has an account trusted to manipulate AD ... >> It posts a form to an ASP page, ... >> Since what you want to do sounds like it will require admin privileges, ...
    (microsoft.public.vb.database)
  • Re: Account control
    ... control is there something I can use to show me the current delegation? ... They set my personal admin account up as a member of the 'domain ... Our enterprise admin group only has the administrator account in it. ...
    (microsoft.public.windows.server.active_directory)