rights delegation

T

Tech-Jeff

Hi,

So recently one of our technicians changed the password of a service accounts not knowing that this SA is used in one of the backups which stopped due to authentication issue. So we decided to create a service account for technicians to use in doing the following:

1. Create an AD login

2. Joining a computer in a domain

So here are so far the steps I did:

1. right click on the domain and selected 'Delegate Control' > Add the user > select 'Create a custom task to delegate' > selected the 2nd radio button 'Only the following objects in this folder' and ticked on the checkbox below 'Create selected objects in this folder' under the long list selected the following:

account objects

user objects

computers onjects

Clicked apply and went to group policy management > Default Domain Controller policy > added to 'Allow to login locally'

So I tested the account, it was able to login to the domain controller but every time I open 'Active Directory Users and Computers' or Server Manager' it prompts for the domain admin credentials.

Any idea on this?

Thanks

TECH-JEFF

Continue reading...
 
Back
Top Bottom