Re: How to give permissions



Hi,

For adding computers to domain, you can give specific users permission "add
workstations to the domain". Best thing to do would be to create a group
called e.g. "Permissions to add workstations to the domain". Now give this
group "add workstations to the domain" permissions on Default Domain
Controller policy.

For resetting accounts and passwords delegate these permissions to another
(or same) group. In Active Directory Users and Computers right click level
where you want to delegate these permissions (e.g. domain or OU (personally
I would go with OU)) and select Delegate Control and follow the wizard.

Delegate policy-related permissions on a domain, OU, or site using GPMC
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/8efacdf7-9700-4395-9d2a-9e848b1737ee.mspx

--
Mike
Microsoft MVP - Windows Security

"Raji A" <rajia@xxxxxxxxxxxxxxxxxxx> wrote in message
news:OtFZTsmkFHA.3960@xxxxxxxxxxxxxxxxxxxxxxx
> Hi
>
> i want to give permissions for a user group - in this case our helpdesk
> people, to add add workstations to the domain, reset accounts and
> passwords, setup printers, etc.
> Can they use the RUNAS command to use this account, rather than use a full
> log in.
>
> Any pointers and what is required.
>
> RajiA
>
>


.



Relevant Pages

  • Software Deployment to Machines
    ... Have you given the workstations read permissions on the ... I've got Office installing on boot up on the workstations ... >I created a domain local security group and made the ...
    (microsoft.public.windows.group_policy)
  • Re: UPGRADE SMALL NETWORK
    ... > the old server and bringing the new one online. ... SIDs, permissions, etc. ... new user profiles on all 2000/XP workstations, ...
    (microsoft.public.windows.server.general)
  • Very eerie delegates problem
    ... The setup is an Exchange 2003 server, running on Windows 2000 server, ... or permissions (the ... Once Outlook is closed and restarted, that delegate is still there, ... This problem was occurring on two computers. ...
    (microsoft.public.exchange.clients)
  • Re: adding workstations to a Win2k domain
    ... The "Add workstation to domain" user right is NOT required to add ... You only need to delegate the ... there is a built in limit of 10 computers that anyone can add to ... > I am trying to delegate permissions to allow a group of people to add ...
    (microsoft.public.windows.server.active_directory)
  • Re: Configuration Error for User Accounts
    ... Check the folder installation, or you can also donwload from sysinternals the Filemon tool runas administrator to check where the permissions are beeing denied, you can also check it with regmon. ... I think it is more than just this one program, since we have another program that uses a shared database on the server that everyone has full access to and when I load that program up I get Path / File Access Error 75. ... with the delete profile at logoff to keep the workstations clean. ...
    (microsoft.public.windows.server.active_directory)