Click here to get back home

domain access control for local user of domain computer?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
domain access control for local user of domain computer? geekyguy 04-03-2008
Posted by geekyguy on April 3, 2008, 5:14 pm
Please log in for more thread options
Hi All: I have a server 2003 domain with some member servers and client
computers.

My desktop is Vista, and the computer is part of the domain. I'm logging on
to the desktop as a local user, not a domain user.

I have a shared folder on the DC, with modify permissions for domain users
and read only permissions for everyone.

I can access the share when logged into my desktop computer under a local
account, but I can't write files to the share.

Is there any way to grant my local Vista user account write privileges to
the domain share, without giving "modify" permissions to "everyone"?


Posted by Roger Abell [MVP] on April 9, 2008, 8:20 am
Please log in for more thread options
> Hi All: I have a server 2003 domain with some member servers and client
> computers.
>
> My desktop is Vista, and the computer is part of the domain. I'm logging
> on to the desktop as a local user, not a domain user.
>
> I have a shared folder on the DC, with modify permissions for domain users
> and read only permissions for everyone.
>
> I can access the share when logged into my desktop computer under a local
> account, but I can't write files to the share.
>
> Is there any way to grant my local Vista user account write privileges to
> the domain share, without giving "modify" permissions to "everyone"?

No, not really, but kind of . . .
Access control is based on the principals to which the
access is granted. This can only be done/given to known
principals. To your domain the local account is unknown.
So really, no, you cannot grant to that local account.
However, if you define a domain account that matches in
name and password the local account then things might
work for you, maybe, if your client behaviors allow for
Windows authentication to happen under the covers.
When you have a domain it is better to just use domain
accounts on the joined machines, which solves your
posted issue and solves problems with keeping account
passwords sync'd if you go the matching account route.
Roger



Similar ThreadsPosted
Delegate Control to rename and add/remove computer from domain February 27, 2007, 4:05 pm
How to configure Domain access permissions for a user that would vary based on the computer they log into? June 21, 2006, 11:58 am
Non-Domain computer access September 6, 2005, 3:47 pm
prevent access to shared folder when not on a domain computer July 11, 2005, 8:50 pm
Domain User but not log on local April 6, 2007, 8:19 pm
PKI User certificate auto-enrollment for XP clients not logging onto domain computer May 18, 2007, 11:02 am
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
Delete cached local copy of mandatory profile and non roaming domain user profiles ? May 1, 2008, 5:50 am
Windows domain user is sometimes denied access to server share October 2, 2006, 5:07 am
Child domain laptops autoenrolling user certs but not computer certs May 21, 2008, 4:19 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap