Solved

AD role to grant and remove computer

Posted on 2014-09-09
5
162 Views
Last Modified: 2014-09-14
What AD role should we add to a user in order to grant or remove a computer in AD. Tks
0
Comment
Question by:AXISHK
  • 2
  • 2
5 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 250 total points
ID: 40313716
Here are the steps to delegate that specific permission:
    Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
    In Active Directory Users and Computers, click View, and then click to select Advanced Features.
    Right-click Computers, and then click Properties.
    Click the Security tab, and then click Advanced.
    In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.
    In the Permission Entry for Computers dialog box, click This object only in the Apply onto list.
    In the Permissions list, find the Delete Computer Objects permission, click to select the Allow check box next to this permission, and then click OK.
    In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.
    Click the Properties tab, and then click computer objects in the Apply onto list.
    In the Permissions list, find the Write All Properties permission, click to select the Allow check box next to this permission, and then click OK three times.

More details from MS:
http://support.microsoft.com/kb/818091
0
 
LVL 4

Assisted Solution

by:Neeraj Kumar
Neeraj Kumar earned 250 total points
ID: 40313719
You need to delegate rights to user to add or remove computer in AD.

Refer the below mentioned article

http://dizzyit.com/2013/05/23/delegate-authority-ad-add-remove-computers/
0
 

Author Comment

by:AXISHK
ID: 40313832
can we simply grant users to accout or backup operators to get this right ? Tks
0
 
LVL 29

Expert Comment

by:becraig
ID: 40313842
Domain users should by default have this permission, however the problem will be the permissions at the OU level.

That is why delegation is the best way to approach this:
e.g. your have an OU for computers for the accounting department in an "ACCOUNTS" OU you would not want to have regular domain users add / remove as such this is generally explicitly denied in secure environments.

If you want to give this ability to a group of users, I would suggest creating a new security group and adding the members you want to give this permission to the group, then delegating the right over that specific OU to that group.
0
 

Author Closing Comment

by:AXISHK
ID: 40322340
Tks
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question