Solved

Grant Permissions to Create/Delete or Modify Computer Objects

Posted on 2006-06-09
5
1,179 Views
Last Modified: 2011-10-03
We have a tech helping us out at the office and he will be required to join some machines to the domain. We have granted him both the "Create Computer Objects" and the "Delete Computer Objects" permissions so that he can continue joining computers to the domain. The problem I'm having now is that he gets a permissions error when he simply tries to rename a computer already joined to the domain. I don't see any "Modify Computer Objects" permissions. As a workaround he has to join the computer to a workgroup, then back to the domain. We'd like to be able to just give him the ability to rename the computer, though...so how do I grant this privelage?
0
Comment
Question by:DVation191
5 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 16870608
renaming a computer is a tool delegated to the administrator of the machine, you can try the power users group but i am not sure if that will even allow i
0
 
LVL 2

Expert Comment

by:krais99
ID: 16871580
There is a default group in the domain called "Account Operators"  

Excerpt from Microsoft:
"Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. Members of this group can log on locally to domain controllers in the domain and shut them down. Because this group has significant power in the domain, add users with caution."

I'm not sure how much freedom you wish this tech to be able to have, as this group would also give him access to users accounts and user groups with the exception of the domain admins.

Todd
0
 
LVL 20

Author Comment

by:DVation191
ID: 16872298
That *may* be the best solution. I would think you should be able to add someone to that group and still explicitly deny the person the ability to modify user accounts, right?
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
ID: 16872374
Create a Security Group just for this person.
On the Properties of the domain (or a sub OU that contains all the computer accounts), select the Security tab.
Add this new Security Group.
Select the Advanced button.
Double click the new security group to open the Special Permissions applet.
Select Clear All.
In the dropdown, select Computer Objects
In the permissions, select Full Control.

This should give the new Security Group full control of all computer accounts.

0
 
LVL 20

Author Comment

by:DVation191
ID: 16872479
Perfect! Thanks Netman66.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Trust one-way issue 2 54
Remove the ability to reboot servers from helpdesk user's. 14 58
ADMT Intra Forest migration questions 7 132
shadow copies 7 71
So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now