DSACLS and joining a domain

From: Ed Little (SPAMlittle_eddieME_at_hotmail.comNOT)
Date: 05/04/05

  • Next message: Herb Martin: "Re: Inheritable ACE doesn't inherit (code included)"
    Date: Wed, 04 May 2005 20:31:57 GMT
    
    

    Hello,

    I am wondering what the minimum permissions needed to join a computer to a
    domain are? I would like to autocreate computer objects using dsadd, and
    them set the appropriate permissions using dsacls. Seems easy enough, but
    it is pretty slow. When adding a computer in ADUC, and specifying the
    group/user who can join it to the domain, it seems to associated many
    unnecessary permissions. Maybe they are all needed, but mimicing these
    settings with dsacls takes for ever. Any ideas?

    Thanks a bunch.

    Ed


  • Next message: Herb Martin: "Re: Inheritable ACE doesn't inherit (code included)"

    Relevant Pages

    • Re: Delegation in AD not working
      ... That is why I wanted dsacls, it is the most accurate display of what is going on ... permissions tab so anything applied to an OU will not impact one of these IDs ... > CHILD ...
      (microsoft.public.win2000.active_directory)
    • Re: Audit exchange 2000 permission
      ... You can use ADSIedit (or AD Users and Computers snap-in in "Advanced" mode, ... are laid out and you can then look at permissions on each object. ... allows you to specify a given object in the AD (such as the Exchange ... commands into DSACLS. ...
      (microsoft.public.exchange2000.general)
    • Re: Win2k - Account Operator not working properly
      ... Verified new user has no special group memberships (only default ... Verified that the new user account can modify objects at the top level OU ... Ran DSACLS on the top level OU and received the following output (only ... are there some required permissions missing? ...
      (microsoft.public.windows.server.active_directory)
    • Re: Delegation in AD not working
      ... but the dsacls in no way looks like the ... Advance tap in Security: ... {This object is protected from inheriting permissions from ... Effective Permissions on this object are: ...
      (microsoft.public.win2000.active_directory)
    • Re: Corrupted object in AD?
      ... If I attempt to use /resetDefaultDACL with the ADAM version of dsacls ... Specified operation failed with ldap error: ... >> permissions were as before and the correct Everyone permissions were ...
      (microsoft.public.windows.server.active_directory)