Windows Thread, types of administrator account in Technical; Hello All,
Im a bit confused with types of administrator;
Basically i want my technicians to be able to have ...
-
29th September 2006, 10:54 AM #1
- Rep Power
- 0
types of administrator account
Hello All,
Im a bit confused with types of administrator;
Basically i want my technicians to be able to have read access to the active directory, and be able to reset passwords on acounts
They also must be able to add / remove machines from the domain.
I've tried account operators, but this doesnt let them do the adding / removing machines, and domain admins seems to give them more or less full control in AD.
What would you suggest?
-
-
IDG Tech News
-
29th September 2006, 10:58 AM #2 Re: types of administrator account
<Removed>
My original post wasn't worth reading!
Wes
-
-
29th September 2006, 11:00 AM #3 Re: types of administrator account
You need to use the delegation of authority wizard. Resetting passwords is easy from that and if you have your machines in an OU of their own then you can delegate them more permissions over that than containers with users in etc.
-
-
29th September 2006, 11:07 AM #4 Re: types of administrator account
With regards to ChrisH check this website address for a step by step guide:
http://www.microsoft.com/technet/pro...p/ctrlwiz.mspx
Wes
-
-
29th September 2006, 11:16 AM #5
- Rep Power
- 0
Re: types of administrator account
this is great, thanks a lot.
One thing though...
i forgot to mention the domain setup, basically its mostly 2003 but one of the DC's is 2000 (dont snigger)
Will it still work?
-
-
29th September 2006, 11:20 AM #6 Re: types of administrator account
Erm...? I believe it won't I think 2000 cripples the extra functionality of 2003 but I think Chris will know better than I.
Wes
-
-
29th September 2006, 11:31 AM #7
- Rep Power
- 0
Re: types of administrator account
You can have domain controllers running Windows 2000 Server in a Windows 2003 domain. You just need the most recent version of adminpak.msi to be manage it from Windows 2000 or XP.
-
-
29th September 2006, 11:37 AM #8 Re: types of administrator account
Yeah, but you wont be able to raise the domain functional level (and get the extra features) to Windows 2003 Server.
-
-
29th September 2006, 12:25 PM #9
- Rep Power
- 0
Re: types of administrator account
ok,
started to look at this, and it could be the solution...
it will work nicely for controlling what they can and cant see in the active directory, however I still cant figure out what permissions to give to allow a non domain admin the ability to join a computer to a domain.
I've added my test user to a group called technicains, and using the delegate control wizard i've allowed the test user to be able to create computer accounts (which works) but when i log on to a machine as that test user, the network ID settings are greyed out.
What am i doing wrong~?
-
-
29th September 2006, 12:45 PM #10 Re: types of administrator account
Did you also assign them the 'add computers to domain' user right?
-
-
29th September 2006, 12:57 PM #11
- Rep Power
- 0
Re: types of administrator account
yes, here is what i have done in full
made a new group "technicians"
made a new user "penguin", who is a standard user not an admin
made a new container "test"
added penguin to technicians
delegated required control over test ou
gone to default domain policy, computer configuration, windows settings, security settings, local policies, user rights assignment and given the group technicians "add workstations to domain"
penguin can now do the things in the test ou i want, and not the things i dont great.
However if penguin logs onto a workstation and goes to the network ID settings, all options are greyed out (even after a forced policy refresh)
Basically I need to ask a new question;
how to i allow a non administrator user to join a machine to the domain (for example a syspreped out of the box machine)
Mathew
-
-
29th September 2006, 01:01 PM #12
- Rep Power
- 0
Re: types of administrator account
The way I thought it worked is that any user account can add up to 10 computers to a domain, if they need to add more they will need to be a member of the account operators group or have permissions delegated to them in AD.
I would guess the change name button is greyed out because they are not local administrators. Perhaps you should create a "tech" group with all of your IT staff in the group and add it to the local administrators groups on your PCs (doable through restricted groups in group policy or manually).
MS article
-
-
29th September 2006, 01:01 PM #13 Re: types of administrator account
You can't do that with a domain account. You need a local group on the machine with 'add computer to domain' rights.
-
-
29th September 2006, 01:06 PM #14
- Rep Power
- 0
Re: types of administrator account
that explains it then;
so am i right in saying, other than making my technicians member of domain admins (and giving them unwanted access to the AD) there is no way i can let them add remove and chage machine identifications?
-
-
29th September 2006, 01:07 PM #15 Re: types of administrator account
They can if the machine is already on the domain. But it's a bit pointless then.
-
SHARE: 
Similar Threads
-
By Mauger in forum Network and Classroom Management
Replies: 5
Last Post: 9th January 2008, 11:38 AM
-
By mmoseley in forum Network and Classroom Management
Replies: 4
Last Post: 27th October 2007, 10:47 PM
-
By mark80 in forum MIS Systems
Replies: 6
Last Post: 15th May 2007, 03:35 PM
-
By tosca925 in forum Windows
Replies: 20
Last Post: 3rd July 2006, 05:02 PM
-
By Gatt in forum Windows Vista
Replies: 0
Last Post: 2nd April 2006, 09:51 AM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules