Click here to get back home

Rights required to allow changing directory ownership?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Rights required to allow changing directory ownership? Joe Hegyi 08-30-2005
Posted by Joe Hegyi on August 30, 2005, 3:37 pm
Please log in for more thread options
'm trying to use XCACLS.VBS to allow our help desk to change the owner on a
user's home directory when it is being created. The command I use is:
cscript xcacls.vbs \SERVER\users\USERID /T /S /E /O "DOMAIN\USERID"

It works fine under my account, which has Domain Admin rights, but the help
desk techs get the following error when they run it:

Error -2147024891: occurred in connecting to server. (Msg#3203)
Error description: Access is denied.

Operation Complete
Elapsed Time: 5.859375E-02 seconds.

Ending Script at 8/29/2005 4:10:32 PM

They have full control on the directories. I've tried giving the help desk
group both "take ownership" and "restore files" user rights on the file
server, but it still doesn't work. Any ideas?

Thanks,
Joe




Posted by Roger Abell [MVP] on August 31, 2005, 6:39 am
Please log in for more thread options
I have not tested in a "change" owner scenario where the changing
account is not the current owner, but it may be that the user right
to Take ownership of objects is what is needed.
If that is the case, that there is no lesser way to allow your scenario,
then you likely would not want to grant this User right to helpdesk.
--
Roger

"Joe Hegyi" <jhegyiATcenturysuretyDOTcom> wrote in message
> 'm trying to use XCACLS.VBS to allow our help desk to change the owner on
> a user's home directory when it is being created. The command I use is:
> cscript xcacls.vbs \SERVER\users\USERID /T /S /E /O "DOMAIN\USERID"
>
> It works fine under my account, which has Domain Admin rights, but the
> help desk techs get the following error when they run it:
>
> Error -2147024891: occurred in connecting to server. (Msg#3203)
> Error description: Access is denied.
>
> Operation Complete
> Elapsed Time: 5.859375E-02 seconds.
>
> Ending Script at 8/29/2005 4:10:32 PM
>
> They have full control on the directories. I've tried giving the help desk
> group both "take ownership" and "restore files" user rights on the file
> server, but it still doesn't work. Any ideas?
>
> Thanks,
> Joe
>




Similar ThreadsPosted
Changing local file rights July 27, 2005, 11:00 am
Modify rights to single file in a directory with only list permiss September 21, 2006, 4:48 pm
Unable to take ownership October 16, 2005, 4:09 pm
Granting Users Ownership Permissions September 10, 2006, 12:04 pm
W2k3 License key and ownership question October 24, 2006, 9:22 am
MS05-046 required? October 17, 2005, 4:32 am
Domain name required? April 12, 2007, 6:56 pm
Permissions required for the Cluster service account? July 7, 2006, 6:51 am
Is third-party middleware required when deploying smartcards? October 1, 2007, 12:02 pm
Hacked 2003 SBS Server - temp fix required April 13, 2008, 2:35 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap