Solved

AD role to grant and remove computer

Posted on 2014-09-09
5
160 Views
Last Modified: 2014-09-14
What AD role should we add to a user in order to grant or remove a computer in AD. Tks
0
Comment
Question by:AXISHK
  • 2
  • 2
5 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 250 total points
ID: 40313716
Here are the steps to delegate that specific permission:
    Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.
    In Active Directory Users and Computers, click View, and then click to select Advanced Features.
    Right-click Computers, and then click Properties.
    Click the Security tab, and then click Advanced.
    In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.
    In the Permission Entry for Computers dialog box, click This object only in the Apply onto list.
    In the Permissions list, find the Delete Computer Objects permission, click to select the Allow check box next to this permission, and then click OK.
    In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.
    Click the Properties tab, and then click computer objects in the Apply onto list.
    In the Permissions list, find the Write All Properties permission, click to select the Allow check box next to this permission, and then click OK three times.

More details from MS:
http://support.microsoft.com/kb/818091
0
 
LVL 4

Assisted Solution

by:Neeraj Kumar
Neeraj Kumar earned 250 total points
ID: 40313719
You need to delegate rights to user to add or remove computer in AD.

Refer the below mentioned article

http://dizzyit.com/2013/05/23/delegate-authority-ad-add-remove-computers/
0
 

Author Comment

by:AXISHK
ID: 40313832
can we simply grant users to accout or backup operators to get this right ? Tks
0
 
LVL 29

Expert Comment

by:becraig
ID: 40313842
Domain users should by default have this permission, however the problem will be the permissions at the OU level.

That is why delegation is the best way to approach this:
e.g. your have an OU for computers for the accounting department in an "ACCOUNTS" OU you would not want to have regular domain users add / remove as such this is generally explicitly denied in secure environments.

If you want to give this ability to a group of users, I would suggest creating a new security group and adding the members you want to give this permission to the group, then delegating the right over that specific OU to that group.
0
 

Author Closing Comment

by:AXISHK
ID: 40322340
Tks
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question