User privileges

User privileges

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
User privileges Amjad Zogby 03-14-2006
`--> Re: User privileges Roger Abell [MV...03-15-2006
Posted by Amjad Zogby on March 14, 2006, 2:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Hi All,

I am trying to give a user the following privileges in an MS2003 Active
Directory environment:

This user must be able to:

1-Logon to the server locally and remotely trough terminal services
2-Backup and restore data
3-create users and mailboxes
4-Join workstations to the domain


This user must be unable to:

1-Change the permission on a folder or file.
2-Take the ownership of a folder or file
3-Make himself member of the administrators group

Any ideas on how this can be done?

Thank you all,




Do u have an idea how this can be done?

Posted by Roger Abell [MVP] on March 15, 2006, 3:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Please do not take this incorrectly, but I would strongly encourage
you to do some research into how Windows Active Directory is
managed. I say this only because your stated needs show you have
a fairly sophisticated deployment (AD + Exchange, with delegated
management), and also as all of these stated needs are pretty much
standard things. If you spend some time becoming informed on
the basics of the system then it is much more likely that you will
have a good experience, with a system more likely to remain
healthy, stable, and effectively trimmed to your needs.

Most of what you are after is done with
User Rights (1, 2, and 4)
Group membership (2)
AD delegation of control (3 - create users)
I am not an Exchange person so I leave 3 - mailboxes to another.

> 1-Logon to the server locally and remotely trough terminal services
user right to log on locally + membership in the Remote Desktop users
group, + enable use of remote desktop in system properties
> 2-Backup and restore data
two different user rights, backup and restore
> 3-create users
see delegation of control - there is a wizard in the context menu
(right click) of AD container objects
> 4-Join workstations to the domain
there is a user right named almost just like that


>
> Hi All,
>
> I am trying to give a user the following privileges in an MS2003 Active
> Directory environment:
>
> This user must be able to:
>
> 1-Logon to the server locally and remotely trough terminal services
> 2-Backup and restore data
> 3-create users and mailboxes
> 4-Join workstations to the domain
>
>
> This user must be unable to:
>
> 1-Change the permission on a folder or file.
> 2-Take the ownership of a folder or file
> 3-Make himself member of the administrators group
>
> Any ideas on how this can be done?
>
> Thank you all,
>
>
>
>
> Do u have an idea how this can be done?



Similar ThreadsPosted
Surfing with User privileges January 28, 2006, 7:37 am
how to success OpenScManager for local machine when logged in with a user don't have administrator privileges May 7, 2008, 4:34 am
Special privileges assigned to new logon?? January 12, 2006, 5:01 pm
Active Directory Admin privileges April 28, 2006, 8:59 am
Detecting Admin Privileges Via Code July 22, 2008, 2:36 pm
How do I verify System Administrator Privileges in Windows ME November 8, 2005, 12:29 am
Need Password to Access Administrator Privileges on home PC June 6, 2007, 9:34 pm
User Profiles being automatically created for local user accounts March 24, 2006, 9:45 am
multiple comp. user- general security user September 24, 2006, 3:51 pm
PKI email encryption varies from user to user October 18, 2006, 2:09 pm

The site map in XML format XML site map

Contact Us | Privacy Policy