Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Example NDS
[ROOT]
---Company (O)
---A (OU)
---B (OU)
---C (OU)I would like to have a user that exists in "a.company" to be able to CREATE users in ONLY "a.company", be able to change ANY users passwords in "a.company" and CREATE home directories and be able to assign appropriate rights to that directory..
These are the things I think / know I need to do but please advise:
1. Make this user a trustee of "a.company" and give that person CREATE and BROWSE object rights.
2. Make this users a trustee of the USERS directory and give them READ, CREATE...PROBLEMS!
1. I don't want this user to be able to read files from user home directories so I did not give them FILE SCAN rights to the USERS directory.... BUT in order for them to be able to give the normal "home direcoty rights" to any user this person creates I must give them "ACCESS CONTROL" rights to that directory which in turn gives them the ability to change those rights thus giving them FILE SCAN, DELETE, etc... which I CANNOT allow....
2. What NDS right do I need to give to the users "a.company" trustee assignment so they can change passwords...
I need some suggestions...Thanks in advance!
-LANce

To Change the passwords they would need Supervisor rights, which obviously you won't want to grant. However, there are utilities avaiable to allow changing passwords without granting supervisor rights. Check on NetwareFiles.com for the utils.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |