Account Operator Security Rights



This is a question of curiosity more than anything else, since the problem
has been resolved.

I'm running Windows Server 2003 SBS.
I wanted to give a user the ability to modify members of E-Mail Distribution
lists which are created as ActiveDirectory Security Groups with Exchange
E-Mail addresses.

In AD Users and Computers, I opened the secuirty group that I wanted to
allow changes to and looked at the Security tab. "Account Operators" was
already included on that tab with "Full Control" rights.
I added the user who would be making the changes to the "Account Operators"
group, and expected this would permit them to make changes to that list.

When the user tested this they got a message stating that they did not have
security permissions to make changes to the list. As a note, the user had
logged off and back on after the change to their account.

Next, I added the individual user to the Security tab of the list, and gave
that user "Full Control". Once that was done the user is able to make
changes successfully.

I'm curious why the rights didn't flow through the Account Operators group
to provide the user with the rights they needed. I prefer to never assign
individual users explicit rights to anything. Rather I like to assign users
to groups and give groups rights. In this case that didn't seem to work.
Any thoughts on why that might be?

Thanks,
--David


.



Relevant Pages

  • Re: Account Operators users changing others Account Operators user
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Claude Lachapelle wrote: ... Each time I'm resetting Acount Operators group rights at the top level OU's structure, we have to drill down the structure to make sure every OU is inheriting from parent. ... This kind of behavior explain for what a lot of companies are giving full rights to everybody (account operators are Domain Admins!), since after using these builtin groups first, they are having troubles resetting passwords on somes accounts... ...
    (microsoft.public.windows.server.active_directory)
  • Re: Police State America - Criticize Bush II...No flying for you
    ... is un-manned would contitute a 'denial of rights'. ... Constitution ... The government has no authority nor a legitimate power to intervene. ... and Selectee lists constitute a list of people who, ...
    (talk.politics.guns)
  • RE: Separation of Content approval rights on Areas
    ... > Below are the rights that a user has by default when they ... > View, insert, edit, delete listings; ... > Add Items - Add items to lists, ... > SharePoint document libraries, and customize Web Part ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Account Operators users changing others Account Operators user
    ... but does they are doing the same thing to OU's security? ... since I'm having trouble keeping Account Operators group ... rights on somes OU's in a problematic Active Directory. ... Does it exist a way for an account operators member to change/reset ...
    (microsoft.public.windows.server.active_directory)
  • Re: Mapping to W2003 user rights/access?
    ... > when it comes to access/user rights. ... I believe Clustering should need maximum Adminrights on the Cluster. ... > 6) Is there a granular delegation setting or something ... I wouldn't even use Account Operators, ...
    (microsoft.public.windows.server.migration)