Re: GPO Management Delegation
- From: "Ace Fekay [Microsoft Certified Trainer]" <firstnamelastname@xxxxxxxxxxx>
- Date: Fri, 10 Oct 2008 23:25:49 -0400
In news:02F99281-87D3-41F8-9498-1BB99CF3D0D7@xxxxxxxxxxxxx,
sevensixtwo187 <sevensixtwo187@xxxxxxxxxxxxxxxxxxxxxxxxx> requesting assistance, typed the following:
It is just for the parent. Using a test account that should be able
to create GPOs but can't, I COULD create a folder in the Policies
folder. This is indeed perplexing.
Not necessarily. Matter of fact, it makes sense because domain (not local) GPOs have two parts, the Group Policy Container that's in Active Directory, and the Group Policy Templates, that you see in the Sysvol folder under the Policies folder. So there are actually two sets of permissions that govern what can be done with a GPO.
Also, if you think about it, when you use the delegation wizard, there's certain nuances to be dealt with, such as inheritance. One example is if you delegate to a specifi OU, it will not apply to child OUs. You would have to delegate the child as well if you want them to have that ability. But that doesn't appear to be the issue here.
http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_23601858.html
What tools are they using to ceate the GPO? GPMC or in the ADUC? Or did you simply create a separate MMC for them and copied over the necessary ADUC files (adprop.dll and dsadmin.dll) and the MMC file to their desktop or Start menu? If so, do they have local desktop admin rights? Have the users been blocked in a Rights somewhere, possibly part of another group, concerning accessing a DC remotely?
Ace
.
- Follow-Ups:
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- References:
- GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: Meinolf Weber
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: Ace Fekay [Microsoft Certified Trainer]
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: Ace Fekay [Microsoft Certified Trainer]
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: sevensixtwo187
- Re: GPO Management Delegation
- From: Ace Fekay [Microsoft Certified Trainer]
- Re: GPO Management Delegation
- From: sevensixtwo187
- GPO Management Delegation
- Prev by Date: Re: build now, join later
- Next by Date: Re: build now, join later
- Previous by thread: Re: GPO Management Delegation
- Next by thread: Re: GPO Management Delegation
- Index(es):
Relevant Pages
|