Allow users to change Description attribute for computer account

Allow users to change Description attribute for computer account

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Allow users to change Description attribute for computer account rickb 07-11-2005
Posted by =?Utf-8?B?cmlja2I=?= on July 11, 2005, 5:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Windows 2003 AD.

All computer names are similar and are incremented by number 0001-9999.

I found a script on technet from the scripting guys. Script works fine for
me (I'm a domain admin), but fails for other users. The second part to the
article was to give the users permissions to change the Description
attribute. I don't necessarily want to give them the keys to the kingdom to
accomplish this. Is this the group policy that allows the user to join the
domain? can anyone shed some light?

here's a link to the article:
http://www.microsoft.com/technet/scriptcenter/resources/qanda/apr05/hey0429.mspx



Posted by Steven L Umbach on July 11, 2005, 7:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
By default a regular user can join a computer to the domain up to ten times.
You can permanently give a user the ability to join computers to the domain
by giving a users group create computer objects permission on the domain or
computers container. This is called delegation of authority. You can right
click the domain or a container and select delegate control to start the
delegation wizard which has preset categories or you can create custom ones.
The delegation wizard simply changes AD permissions on the object. You also
for instance could select a container, right click
properties/security/advanced and then add or edit permissions. Then select
apply onto computer object and look for the needed permissions in the object
or properties tab. I believe read/write description is in the properties
tab. --- Steve


> Windows 2003 AD.
>
> All computer names are similar and are incremented by number 0001-9999.
>
> I found a script on technet from the scripting guys. Script works fine
> for
> me (I'm a domain admin), but fails for other users. The second part to
> the
> article was to give the users permissions to change the Description
> attribute. I don't necessarily want to give them the keys to the kingdom
> to
> accomplish this. Is this the group policy that allows the user to join
> the
> domain? can anyone shed some light?
>
> here's a link to the article:
>
http://www.microsoft.com/technet/scriptcenter/resources/qanda/apr05/hey0429.mspx
>
>



Similar ThreadsPosted
Assign permissions to create other users to Users account November 9, 2006, 4:05 am
how to change all domain user account passwords at once July 8, 2005, 11:01 am
Remote users and AD authentication: Required password change is mi August 19, 2005, 9:38 am
why has my .net account hijacked my computer? November 10, 2005, 12:21 pm
Event 539 with computer$ account August 2, 2006, 12:26 pm
Forcing users to log into Domain account when in workplace May 19, 2007, 3:14 am
read only attribute April 7, 2008, 8:49 pm
Unable to remove Read Only attribute September 27, 2005, 6:16 pm
SerialNumber attribute under Subject field April 20, 2006, 3:30 am
Unable to remove Read-Only attribute from folder July 14, 2005, 10:31 am

The site map in XML format XML site map

Contact Us | Privacy Policy