Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.
Admin Rights
Name: rajoo_sh Date: April 14, 2008 at 21:35:00 Pacific OS: win2k3 server CPU/Ram: core 2 duo 2.2 Product: Intel (assembled machine)
Comment:
Hi,
In a win2k3 domain I want to assign only the domain user's password reset rights to a user, I don't want this user to even view the group policy of the organizational unit. And if possible the other properties of the user object, I want only the password reset option available or something very restrictive.
Name: Jestible Date: April 15, 2008 at 08:02:03 Pacific
Reply:
Huh, can you rephrase it or am I to slow to understand this question?
Holy Wow.
0
Response Number 2
Name: lordstorm Date: April 15, 2008 at 12:53:08 Pacific
Reply:
you can set each user to have the ability to renew their own password and you can also force the user to reset their password when they login the next time. This is all done in the Active Directory/User Properties/Account Tab/Account Options.
0
Response Number 3
Name: rajoo_sh Date: April 15, 2008 at 22:11:17 Pacific
Reply:
Off course I can rephrase it, I want to create an admin user who can reset passwords of other users in any Organizational unit using dsa.msc.
But this admin user should not be able to view the group policies or perform any other action except this password reset.
Its better I hope :-)
0
Response Number 4
Name: Glen Date: April 16, 2008 at 09:56:00 Pacific
Reply:
You can delegate admin rights to users. Open ADUC and right click on the OU. You'll have to do this per OU if you have several. Select Delegate Control. Go through the wizard. There is an option there that will only allow the resetting of passwords.
Summary: Currently we are attempting to set up a mulit-domain forrest in our testing environment. For this example our root domain is dom1.root and our second domain is dom2.local. Both domains are in Window...
Summary: if a domain is running static 2000 then u must be able to assign a group to the admin group as u would a user. !But be warned, this is a verry bad idea giving more then one user domain admin rights. ...
Summary: Hi guys. I have a server i have been experimenting with. I have been working things out for myself with the help of luck, google, books, luck, microsoft site, and luck. I started with no server experi...