rssystems
asked on
Unix Attribute Tab in AD fails unless domain admin
I am having trouble assigning non domain admin accounts permission to alter attributes in the Unix tab for any user account.
Generic error is:
Unable to update the maximum user ID number for the selected NIS Domain
then after clicking OK you get:
Unable to modify the object property values.
Check your credentials
There could be a network problem
Active Directory Domain Services could be down
Contact your system administrator
The articles on the web say add full control to ypserv30.
ypserv30 - the group has full control of the folder and all child objects.
We are running 2003 DFL/FFL and I do have MS Identity Management for Unix installed on one of the 2008r2 domain controllers.
-----------------------
Does the group also need full control of defaultmigrationcontainer3 0? or is there something else to check..
thanks in advance...
Generic error is:
Unable to update the maximum user ID number for the selected NIS Domain
then after clicking OK you get:
Unable to modify the object property values.
Check your credentials
There could be a network problem
Active Directory Domain Services could be down
Contact your system administrator
The articles on the web say add full control to ypserv30.
ypserv30 - the group has full control of the folder and all child objects.
We are running 2003 DFL/FFL and I do have MS Identity Management for Unix installed on one of the 2008r2 domain controllers.
-----------------------
Does the group also need full control of defaultmigrationcontainer3
thanks in advance...
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
"Unable to update the maximum user ID number for the selected NIS Domain"
But we still receive the other generic error below and are unable to make changes without using a domain admin account.
Unable to modify the object property values.
Check your credentials
There could be a network problem
Active Directory Domain Services could be down
Contact your system administrator
We added explicit permissions for a security group with full control to ypserv30 (permissions include r/w for all of the following):
gecos
gidNumber
loginShell
msSFU30Name
msSFU30NisDomain
uid
uidNumber
unixHomeDirectory
unixUserPassword
--------------------------
we also made sure that in the schema under group it does have posixGroup as an auxiliary class under relationship.
Any other suggestions?