Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 2006

Another Way to Provide the Missing Link

RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

In the Reader to Reader article "The Missing Link in Windows' Group Hierarchy" (July 2006, InstantDoc ID 50022), Murat Yildirimoglu and Ugur Duman point out that the Windows' group hierarchy is missing a built-in group that can manage client computers but not domain controllers (DCs) and other crucial servers. To fill this void, they created a Technicians group, placed the Technicians group in the Domain Admins group, then removed the Domain Admins group from the Administrators group in Active Directory (AD) and from the Administrators group on crucial servers. That way, their technicians can add more than 10 workstations to the domain. This procedure seems like a lot of work.

At my company, we also created a group for our support technicians. However, to give this group's members the ability to add more than 10 computers to the domain, we gave them the Create Computer Objects permission in AD for the appropriate organizational units (OUs). We also removed the Add workstations to domain right for authenticated users in Group Policy so that the authenticated users can't add a workstation to the domain. You can access the Add workstations to domain option by navigating to Computer Configuration, Windows Settings, Local Policies, User Rights Assignments.

With this setup, our support technicians can add workstations to the domain without running into the default 10-workstation limit. We made this group a Restricted Group for additional security.
—Bill Brower

End of Article



Reader Comments
Bill, your solution depends on giving Create Computer objects permission to a such group. But quotas and permissions are two different animals. Take the file permissions and disk quota for example. You can have NTFS write permission on a certain disk but if there is a disk quota restricting the disk usage to only 100 MB, you can create files only up to 100 MB. Permissions do not help us overcome the quota restrictions. So, your solution is not the solution indeed.

muraty September 12, 2006 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...


Active Directory (AD) Whitepapers Meeting Compliance Objectives in SharePoint

Email Controls and Regulatory Compliance

Related Events Troubleshooting Active Directory

Deep Dive into Windows Server 2008 R2 presented by John Savill

Troubleshooting Group Policy, eLearning series

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement