Click here to get back home

OU delegation

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
OU delegation tin 07-26-2007
|--> Re: OU delegation Roger Abell [MV...07-26-2007
Posted by tin on July 26, 2007, 12:08 pm
Please log in for more thread options
Hello, I've delegated full controll to a security group to an OU, but that
group still not able to manage computers remotely. For instance, they cannot
perform administrative tasks on computers in that are in this OU. I know I
can run a script to add this security group to all the active computers in
that OU but I just wanted to know if there's another way to do this? I dont
think you can automate this through GPO though, but I could be wrong.

Thanks,
TC



Posted by Roger Abell [MVP] on July 26, 2007, 2:26 pm
Please log in for more thread options
Restricted Group definitions in GPO may be used to add a domain
group as a member in a machine local group. Until the computers
in that OU believe that the accounts with the OU delegation have
rights on/over them the OU delegation will be limited to privileges
on the computer objects in AD (as distinct from the computers).

Roger

> Hello, I've delegated full controll to a security group to an OU, but that
> group still not able to manage computers remotely. For instance, they
> cannot perform administrative tasks on computers in that are in this OU. I
> know I can run a script to add this security group to all the active
> computers in that OU but I just wanted to know if there's another way to
> do this? I dont think you can automate this through GPO though, but I
> could be wrong.
>
> Thanks,
> TC
>



Posted by jwgoerlich on July 26, 2007, 8:02 pm
Please log in for more thread options
Interesting. I have always simply added the groups to the computers'
local Adminstrators group. The same thing could be done by adding
Administrators to the "Restricted Groups" setting and specifying the
delegated group.

This setting is under:

Computer Configuration
Windows Settings > Security Settings > Restricted Groups

Regards,

J Wolfgang Goerlich

> Hello, I've delegated full controll to a security group to an OU, but that
> group still not able to manage computers remotely. For instance, they cannot
> perform administrative tasks on computers in that are in this OU. I know I
> can run a script to add this security group to all the active computers in
> that OU but I just wanted to know if there's another way to do this? I dont
> think you can automate this through GPO though, but I could be wrong.
>
> Thanks,
> TC



Posted by Roger Abell [MVP] on July 27, 2007, 2:37 am
Please log in for more thread options
> Interesting. I have always simply added the groups to the computers'
> local Adminstrators group. The same thing could be done by adding
> Administrators to the "Restricted Groups" setting and specifying the
> delegated group.
>
> This setting is under:
>
> Computer Configuration
> Windows Settings > Security Settings > Restricted Groups

Just to be clear, the way one would do this, add a domain group
named for example OuControllers to the Administrators group
on all machines in the OU, is to add a Restricted Group definition
in a GPO linked to that OU. The Restricted Group definition would
be for the group OuControllers, one would leave the Members list
empty (not set) and would type in Administrators as the one entry
in the Member-Of list.

Roger

>> Hello, I've delegated full controll to a security group to an OU, but
>> that
>> group still not able to manage computers remotely. For instance, they
>> cannot
>> perform administrative tasks on computers in that are in this OU. I know
>> I
>> can run a script to add this security group to all the active computers
>> in
>> that OU but I just wanted to know if there's another way to do this? I
>> dont
>> think you can automate this through GPO though, but I could be wrong.
>>
>> Thanks,
>> TC
>
>



Posted by tin on July 27, 2007, 3:08 pm
Please log in for more thread options
I came across this one policy but wasn't sure what it for.

Thank you so much for all you guys help!

>> Interesting. I have always simply added the groups to the computers'
>> local Adminstrators group. The same thing could be done by adding
>> Administrators to the "Restricted Groups" setting and specifying the
>> delegated group.
>>
>> This setting is under:
>>
>> Computer Configuration
>> Windows Settings > Security Settings > Restricted Groups
>
> Just to be clear, the way one would do this, add a domain group
> named for example OuControllers to the Administrators group
> on all machines in the OU, is to add a Restricted Group definition
> in a GPO linked to that OU. The Restricted Group definition would
> be for the group OuControllers, one would leave the Members list
> empty (not set) and would type in Administrators as the one entry
> in the Member-Of list.
>
> Roger
>
>>> Hello, I've delegated full controll to a security group to an OU, but
>>> that
>>> group still not able to manage computers remotely. For instance, they
>>> cannot
>>> perform administrative tasks on computers in that are in this OU. I know
>>> I
>>> can run a script to add this security group to all the active computers
>>> in
>>> that OU but I just wanted to know if there's another way to do this? I
>>> dont
>>> think you can automate this through GPO though, but I could be wrong.
>>>
>>> Thanks,
>>> TC
>>
>>
>
>



Similar ThreadsPosted
EFS and Delegation June 8, 2005, 10:30 am
Delegation problem January 22, 2006, 1:43 pm
Kerberos delegation December 7, 2006, 12:53 pm
Kerberos/ASP/Delegation/W2K3 July 19, 2005, 2:24 pm
RODC 2008 account and delegation April 17, 2008, 3:50 am
Delegation using GSSAPI in Microsoft Kerberose based realm November 26, 2005, 7:17 am
Reset Passwords, Account operators, Delegation - access denied August 8, 2006, 8:37 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap