Re: DSACLS and joining a domain

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/06/05

  • Next message: Steven L Umbach: "Re: LDAP/S"
    Date: Thu, 5 May 2005 22:44:02 -0500
    
    

    Create computer objects is an special permission in Active Directory that
    you will see on a container such as the domain container or an
    Organizational Unit in advanced page when you add a group to or edit
    permissions for a group. The user right for add workstations to the domain
    will only allow a user to add ten workstations to the domain by default. A
    user does not need that user right if they have the create computer objects
    permission. As far as scripts you might take a look in the Windows Scripting
    Center. --- Steve

    "Eddie Little" <little_eddieSPAM@MEhotmail.NOTcom> wrote in message
    news:W7WdnTGGhIvdI-ffRVn-sg@golden.net...
    > By the looks of it top posting is the norm here so here we go...
    >
    > Thanks Steve, but I am a little confused.
    >
    > Is "create computer objects" a "right" that is able to be set using
    > something like dsacl (or even setacl)? I have a feeling I will have to
    > mimic this ACE with many iterations of dsacls, which has been very
    > inefficient for me. It takes upwards of 20 seconds to apply something
    > like
    > "Reset Password" to one group for one computer object.
    >
    > Maybe there are other ways to achieve this goal? I'm sure others out
    > there
    > automate the creation of computer objects and apply rights to "join the
    > domain" at the same time. It seems a very "normal" thing to do. I was
    > hoping for a simple batch file approach. Something like...
    >
    > @echo off
    > for /f "delims=" %%A in (comp_names.txt) do (
    > dsacls "CN=%%A,OU=Computers,DC=Domain,DC=CA" /I:T /G "Domain\Add Computers
    > Goup:CA;Reset Password;"
    > dsacls...
    > dsacls...
    > )
    >
    > I guess I will look to a PERL or VBScript solution instead. Any insight?
    >
    > Thanks,
    > Ed.
    >
    > "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
    > news:uPCXQZZUFHA.3184@TK2MSFTNGP15.phx.gbl...
    >> I believe the user only needs create computer objects to join computers
    >> to
    >> the domain. --- Steve
    >>
    >>
    >> "Ed Little" <SPAMlittle_eddieME@hotmail.comNOT> wrote in message
    >> news:1jaee.7499$uE3.84@charlie.risq.qc.ca...
    >> > Hello,
    >> >
    >> > I am wondering what the minimum permissions needed to join a computer
    >> > to
    > a
    >> > domain are? I would like to autocreate computer objects using dsadd,
    > and
    >> > them set the appropriate permissions using dsacls. Seems easy enough,
    > but
    >> > it is pretty slow. When adding a computer in ADUC, and specifying the
    >> > group/user who can join it to the domain, it seems to associated many
    >> > unnecessary permissions. Maybe they are all needed, but mimicing these
    >> > settings with dsacls takes for ever. Any ideas?
    >> >
    >> > Thanks a bunch.
    >> >
    >> > Ed
    >> >
    >>
    >>
    >
    >


  • Next message: Steven L Umbach: "Re: LDAP/S"

    Relevant Pages

    • Re: Delegated permission to add computers
      ... This setup was initially done using the delegated control wizard. ... Right now the group has the following permission: ... I am going to try to add Full Control permissions on computer objects to see ... Jeff ...
      (microsoft.public.windows.server.active_directory)
    • Re: Computer Objects
      ... DELETE on the object being moved or DELETE_CHILD on the source container ... > I am trying to find the correct permission to delegate the authority to MOVE ... > delete computer objects is available per OU, but I would also like delegate ...
      (microsoft.public.win2000.active_directory)
    • Re: Delegating permission to add computers to the domain
      ... One minor change to Step 7.... ... Instead of Editing the Existing rights, Add the user or group again to the ... In the end they will have "Create Computer Objects" and "Delete Computer ... > I need to delegate permission to a group of users to add computers to the ...
      (microsoft.public.windows.server.active_directory)
    • Re: Delegating permissions
      ... You should be able to just grant that group the "Create Computer Objects" ... > I need to delegate permission to a group of users to add computers to ... Creating a custom task allowing Object Type = Computer Objects, ...
      (microsoft.public.windows.group_policy)
    • Re: Create a partial admin account
      ... The users can now manually create computer objects and then they can specify who can do the actual join process. ... You can not delegate the ability to do this if they just use the Join Domain Wizards. ... Is there anyway I can create an account with partial admin rights that would allow them to join computers to domain without giving them full admin privleges to the domain or is it an all or nothing situation? ...
      (microsoft.public.windows.server.active_directory)