Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Active Directory Permission

Status
Not open for further replies.

tEkHEd

IS-IT--Management
Jan 29, 2003
261
GB
Hello.

I want to be able to allow my computer objects to add/remove themselves from AD Groups.

I thought that this simply needed the NT AUTHORITY\SELF account to be appropriatly permissioned?

I have set the following permissions on my OU and Group Objects, but am still not able to add the machine to a group via a startup script (running as system obviously :))

Code:
This object	Allow	NT AUTHORITY\SELF	Read all properties
This object	Allow	NT AUTHORITY\SELF	List contents
This object	Allow	NT AUTHORITY\SELF	Generate Resultant Set of Policy (Planning)
This object	Allow	NT AUTHORITY\SELF	Generate Resultant Set of Policy (Logging)
All Subobjects	Allow	NT AUTHORITY\SELF	Read all properties
All Subobjects	Allow	NT AUTHORITY\SELF	List contents
Group objects	Allow	NT AUTHORITY\SELF	Read all properties
Group objects	Allow	NT AUTHORITY\SELF	List contents
Group objects	Allow	NT AUTHORITY\SELF	All control accesses
Group objects	Allow	NT AUTHORITY\SELF	Modify Membership

I have also granted the following rights explicitly for Group Objects:

List Contents
Read All Properties
Read Permissions
Modify Permissions
All Validated Rights
All Extended Rights
Add/Remove self as member
Send As
Send To

Can anyone provide any help on this one please?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top