Re: domain access control for local user of domain computer?



"geekyguy" <geeky@xxxxxxx> wrote in message
news:u3r5Q9clIHA.2396@xxxxxxxxxxxxxxxxxxxxxxx
Hi All: I have a server 2003 domain with some member servers and client
computers.

My desktop is Vista, and the computer is part of the domain. I'm logging
on to the desktop as a local user, not a domain user.

I have a shared folder on the DC, with modify permissions for domain users
and read only permissions for everyone.

I can access the share when logged into my desktop computer under a local
account, but I can't write files to the share.

Is there any way to grant my local Vista user account write privileges to
the domain share, without giving "modify" permissions to "everyone"?

No, not really, but kind of . . .
Access control is based on the principals to which the
access is granted. This can only be done/given to known
principals. To your domain the local account is unknown.
So really, no, you cannot grant to that local account.
However, if you define a domain account that matches in
name and password the local account then things might
work for you, maybe, if your client behaviors allow for
Windows authentication to happen under the covers.
When you have a domain it is better to just use domain
accounts on the joined machines, which solves your
posted issue and solves problems with keeping account
passwords sync'd if you go the matching account route.
Roger


.



Relevant Pages

  • Re: ADAM SP1 on Win2K3 SP1
    ... Assuming SSL on ADAM is working fine and i want to use antoher domain user account as the ADAM service account. ... Do i only need to grant that account READ permission to machine keys and use dsdbutil to change the ADAM service account? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Workaround for 0x8007045A (!)
    ... works if you log on to the administrator account of a workstation attached to ... in a fit of social conscience that might help other WU5 ... domain account under previous versions of SBS were now missing. ... on as domain user and WU5 doesn't work. ...
    (microsoft.public.windowsupdate)
  • Re: ADMTv2 questions
    ... > account to another one. ... > resourses which only the source domain user has permission. ... > The content of SID mapping file should be like below. ... The ACEs for the OLDDOMAIN domain will be preserved. ...
    (microsoft.public.windows.server.migration)
  • Re: Server 2003 Administration Pack Security Flaw?
    ... I'm not able to reproduce this with a test domain user account on my Windows ... the Domain Admin, Enterprise Admin, Administrators, or the Account Operators ...
    (microsoft.public.windows.server.active_directory)
  • Re: server 2003 standard domain user local rights
    ... been domain user accounts available and I thought you said there were none. ... has created a user account locally and given it any type of permissions. ... Setup Server Wizard on the SBS. ... Your Server Wizard to add the Domain Controller role, ...
    (microsoft.public.windows.server.sbs)