Re: Allow users to change Description attribute for computer account

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 07/12/05


Date: Mon, 11 Jul 2005 18:13:00 -0500

By default a regular user can join a computer to the domain up to ten times.
You can permanently give a user the ability to join computers to the domain
by giving a users group create computer objects permission on the domain or
computers container. This is called delegation of authority. You can right
click the domain or a container and select delegate control to start the
delegation wizard which has preset categories or you can create custom ones.
The delegation wizard simply changes AD permissions on the object. You also
for instance could select a container, right click
properties/security/advanced and then add or edit permissions. Then select
apply onto computer object and look for the needed permissions in the object
or properties tab. I believe read/write description is in the properties
tab. --- Steve

"rickb" <rickb@discussions.microsoft.com> wrote in message
news:B5205AD6-C197-422E-B8FC-00C535F4D31B@microsoft.com...
> Windows 2003 AD.
>
> All computer names are similar and are incremented by number 0001-9999.
>
> I found a script on technet from the scripting guys. Script works fine
> for
> me (I'm a domain admin), but fails for other users. The second part to
> the
> article was to give the users permissions to change the Description
> attribute. I don't necessarily want to give them the keys to the kingdom
> to
> accomplish this. Is this the group policy that allows the user to join
> the
> domain? can anyone shed some light?
>
> here's a link to the article:
> http://www.microsoft.com/technet/scriptcenter/resources/qanda/apr05/hey0429.mspx
>
>



Relevant Pages

  • Re: Identify alls Objects in ADS which a specific group has specific permissions
    ... joiners" has the right to create computer objects. ... >>specific group has specific permissions. ... script which can do this for me. ...
    (microsoft.public.win2000.active_directory)
  • Re: What happens to the machine name in AD?
    ... The user needs Write permissions on the computer object to modify all ... usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Trying to use NetJoinDomain API...
    ... Nope I used the delegation wizard to set ACLs, and I also went in and added ... These are the permissions granted to the group, ... Computer Objects ...
    (microsoft.public.windows.server.active_directory)
  • Re: What happens to the machine name in AD?
    ... The normal user doesn't have these permissions, ... > usually grant these rights on the OU that contains the computer objects. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security groups for OUs
    ... permissions on the OU, ... > user in OU2 each seperate and independently managed. ... > Is there any way of restricting an administrator in OU1 adding a user ... > As I have already use delegation wizard to restrict each OUs admin to ...
    (microsoft.public.windows.server.active_directory)