Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Grant Permissions to Create/Delete or Modify Computer Objects

Posted on 2006-06-09
5
Medium Priority
?
1,192 Views
Last Modified: 2011-10-03
We have a tech helping us out at the office and he will be required to join some machines to the domain. We have granted him both the "Create Computer Objects" and the "Delete Computer Objects" permissions so that he can continue joining computers to the domain. The problem I'm having now is that he gets a permissions error when he simply tries to rename a computer already joined to the domain. I don't see any "Modify Computer Objects" permissions. As a workaround he has to join the computer to a workgroup, then back to the domain. We'd like to be able to just give him the ability to rename the computer, though...so how do I grant this privelage?
0
Comment
Question by:DVation191
5 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 16870608
renaming a computer is a tool delegated to the administrator of the machine, you can try the power users group but i am not sure if that will even allow i
0
 
LVL 2

Expert Comment

by:krais99
ID: 16871580
There is a default group in the domain called "Account Operators"  

Excerpt from Microsoft:
"Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain, except the Domain Controllers organizational unit. Members of this group do not have permission to modify the Administrators or the Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. Members of this group can log on locally to domain controllers in the domain and shut them down. Because this group has significant power in the domain, add users with caution."

I'm not sure how much freedom you wish this tech to be able to have, as this group would also give him access to users accounts and user groups with the exception of the domain admins.

Todd
0
 
LVL 20

Author Comment

by:DVation191
ID: 16872298
That *may* be the best solution. I would think you should be able to add someone to that group and still explicitly deny the person the ability to modify user accounts, right?
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 2000 total points
ID: 16872374
Create a Security Group just for this person.
On the Properties of the domain (or a sub OU that contains all the computer accounts), select the Security tab.
Add this new Security Group.
Select the Advanced button.
Double click the new security group to open the Special Permissions applet.
Select Clear All.
In the dropdown, select Computer Objects
In the permissions, select Full Control.

This should give the new Security Group full control of all computer accounts.

0
 
LVL 20

Author Comment

by:DVation191
ID: 16872479
Perfect! Thanks Netman66.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Are you ready to place your question in front of subject-matter experts for more timely responses? With the release of Priority Question, Premium Members, Team Accounts and Qualified Experts can now identify the emergent level of their issue, signal…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question