![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
Local Admin on all machines and add comp to domainthis thread has 11 replies and has been viewed 3114 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#11
|
||||||||
|
||||||||
|
Sounds like you delegated account operator control to this team? The Account Operator group does not grant Read permissions on the built-in OU, so you need to fix your permissions.
Use the delegation control wizard again and create a custom task for the OU. Add Object Type control for computer objects + create/delete objects in this folder. Under permissions set Read/write account restrictions, reset password, validate write to DNS host name, and validate write to service principal name. Should fix your access denied issue. |
|
#12
|
|||||||||||
|
|||||||||||
|
Any authenticated user has read access to almost all of the objects in domain partition (including the built-in Computers and Users containers)
__________________
Guy Teverovsky http://blogs.technet.com/b/isrpfeplat/ "Smith & Wesson - the original point and click interface" |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| change admin password for local comp using batch | hshaik | General Scripting | 3 | 9th April 2007 23:52 |
| Add Domain user/group as winXP local Administrator | ebe75 | GPO | 13 | 25th March 2007 01:04 |
| Win2003 Domain Controller lost Local Admin & Domain Admin pwds | OdinTrisk | Forgot Administrator Password | 2 | 7th January 2007 22:44 |
| New Domain, Need All users to have Local Admin | spepi | GPO | 6 | 27th December 2006 17:15 |
| add comp and user account for a new comp by a script | avivh | General Scripting | 1 | 25th December 2004 22:33 |