Link to home
Start Free TrialLog in
Avatar of Line One
Line One

asked on

special superviewer user creation in windows 2000/2003/2008

I want to create a special user on Windows servers that has the following rights:

right to view all AD objects and properties of those objects but not change or modify
right to view all permissions/ACL lists/security settings but not change or modify
right to view all files/folders etc. but not change or modify any thought  the ID can create modify new Word and Excel files in their home folder

What are the steps to do so?
ASKER CERTIFIED SOLUTION
Avatar of Cliff Galiher
Cliff Galiher
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Line One
Line One

ASKER

Basically it seems I just go to the root and give 'Read' rights in both cases. Is that correct? Also it sounds like it might be best to create a group called superviewer for example and just put the ID in there of the person/persons that these rights are to be given to.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Sorry, I was referring specifically to the AD objects in my comment above.
Thanks for the info.
you bet...thanks for the points!