Link to home
Start Free TrialLog in
Avatar of Corcoran Smith
Corcoran SmithFlag for United Kingdom of Great Britain and Northern Ireland

asked on

AD: changing default permissions for users and objects from DCPROMO

guys. i've taken the first object for legacy compatibility in my AD whilst running DC Promo (see http://www.petri.co.il/images/dcpromo019.jpg ) to see the page; if i then want to change this within the AD; how can i do it? Or if i just have one domain controller; do i have to do another DCPromo, take off AD, and put it back on again??
Avatar of Pber
Pber
Flag of Canada image

Avatar of Corcoran Smith

ASKER

so all that option does is add 'everyone' into the pre-windows 2000' group???  That is ... typically microsoft-y i guess??!
ASKER CERTIFIED SOLUTION
Avatar of Pber
Pber
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
so in there; ideally i should only have authenticated users ...  currently has anonymous logon and everyone
Mine has only Authenticated users and Exchange Domain Servers
awesome cheers. i've got issues doing TRUST back to my old NT4 domain; so seeing whether this is related.  Thanks for your speeeeeedy help Pber.
yeah i'm getting this:

the security database on the server does not have a computer account for this workstation trust relationship (on the windows 2003 box)

this is unusual... googled it. no joy yet.
The 2003 box, is that the AD box?

Have you been able to create a trust at all?  Or is the Windows 2003 server the only problem machine?

yah the PDCE. AD is working ok - combed the logs. DNS is up. netbios is up.

can create it on the 2003 machine, but then on the confirmation, that's when it throws up the error.
damn wins. sorted it. cheers Pber
It's usually always Netbios.
(:
Glad you got that working.