ArtieBall Posted November 15, 2011 Posted November 15, 2011 Our Top Level is OU is 'TJWA'. I have users in 'OU=Administators,OU=TJWA' who cannot authenticate. However all users in OU's under 'OU=Users,OU=TJWA' can authenticate without problem. Any idea's anyone? TIA Artie
nickbro Posted November 15, 2011 Posted November 15, 2011 That's odd. Are your administrators members of the domain users group?
ArtieBall Posted November 17, 2011 Author Posted November 17, 2011 That's odd. Are your administrators members of the domain users group? No, the Administrators group was set up to allow elevated Administrator type privileges with having Domain Admin privileges
Davit2005 Posted November 17, 2011 Posted November 17, 2011 No, the Administrators group was set up to allow elevated Administrator type privileges with having Domain Admin privileges Is there any other reason why the administrators are not members of Domain Users. Administrators can be made members of both Domain Users and Domain Administrators so find the setup a bit weird. Unless Domain Users group has been denied access to something on purpose of course?
ArtieBall Posted November 17, 2011 Author Posted November 17, 2011 Our IT support has been outsourced.... the pseudo Administrators OU has been created by them to give some users elevated Administrator privileges without them being Domain Admins...
Davit2005 Posted November 17, 2011 Posted November 17, 2011 As I said, pretty weird but I do not know the politics etc. or their thoughts/plans for setting it up this way.
mattgrimley Posted November 17, 2011 Posted November 17, 2011 Our IT support has been outsourced.... the pseudo Administrators OU has been created by them to give some users elevated Administrator privileges without them being Domain Admins... But domain users and domain admins are not the same thing.. the "domain users" group has typically very limited access and i would expect any user of the domain to be a member of that group (fundamentally).. As @Davit2005 says we dont know the reasons for it being set up this way, but i would think that is going to be a recurring problem.. (I understand why you wouldnt want outsourced people to have "Domain Admin" rights, but i would think "Domain Users" is fundamental..
Jamo Posted November 17, 2011 Posted November 17, 2011 Are there odd security permissions on the OU itself?
ArtieBall Posted November 17, 2011 Author Posted November 17, 2011 Ok.... Maybe I need to eleborate... Our Domain is now under the control of the Outsource Company.... as the ex Network Manager I am still here in a different role and I have been put into the Administrators OU, but I do not have Domain Admin permissions. I do however have higher permissions than other network users. In the hapconfig file, for the Group "Management" I have set showto="Administrators". I am in the Adminstrators group but I do not see the Management functions when I login.
nickbro Posted November 17, 2011 Posted November 17, 2011 Administrators Group or Administrators OU. Two totally different things. HAP+ only picks up on the Group, the OU is used for populating the user drop down lists.
ArtieBall Posted November 18, 2011 Author Posted November 18, 2011 Is there no way to get HAP to search particular OU's for "showto" etc? It obviously searches OU's under OU=Users, because if in the config file I put showto"Teaching Staff" it works. The Teaching Staff OU is contained in the Users OU. Where does HAP start searching in the tree, can it be tweaked? TIA Artie
nickbro Posted November 18, 2011 Posted November 18, 2011 The showto, only does AD Groups, not AD OUs.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now