Jump to content

Recommended Posts

Posted

Been tidying up security settings etc and the user used to Bind AD was a Domain Admin, which I am looking to change to a stanard user with delegated access.

 

I'm looking at this smoothwall document - https://help.smoothwall.net/FilterFirewall/Content/4Services/1Authentication/2Directories/1Microsoft/Add.htm

 

Prerequisites

In Active Directory, choose or configure a non-privileged user account to use for connecting the domain. The Smoothwall Filter and Firewall stores this account’s credentials, for instance, when backing-up and replicating settings.

 

The account that you use needs permission to modify the Computers container, including being able to create keytab files across the domain or forest.

 

To delegate these permissions to a non-privileged user account, choose Delegate Control on the Computers container, create a custom task to delegate and, for Computer objects, grant the full control, create and delete privileges.

 

 

Am I reading this right as it wants Full Control as well as create and delete privilege's?? Wouldn't full control give those anyway - or should it be give full control to Create and Delete only?

 

Cheers.

Posted
The only permission the Smoothwall AD bind user needs is the ability to add computers to the domain - this is standard for user accounts so unless it has been revoked in the user rights, a normal user account should work fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...