Policy/Permissions Problem

Discussion in 'Active Directory Exams' started by Nelix, Dec 13, 2003.

  1. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Hi All

    I have a problem, while the late network admin was employed he put into place some fairly strict permissions on the network, TOO strict to be honest. We have just set up a machine for a remote user and set it up so that he can dial into the network, the problem starts when he trys to add his local printer in that ....he cant due to the permissions that the machine pickup when it was joined to the domain during the setup procedure, I have tried adding the user to the domain admin group and told him to dial in again hopeing that it would pick up the new permission for this group and allow him to add his local printer and i could them remove him from the domain admins group. This, alas, did not work :hhhmmm :confused2 :confused3 .

    Anyone got ant ideas please.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  2. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    Derek

    The only thing I can come up with is that the mchine account is having a Group Policy applied to it where

    Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Prevent Users from installing Printer Drivers

    is enabled.

    If you had an XP machine with the Group Policy Management Console installed you could easily check this :)
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  3. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    Looks like that could be a distinct possibility phil, thanks for that, I will check it out on monday and let you know.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  4. GGGunit

    GGGunit New Member

    4
    0
    8
    Bonsoir,
    adding the user to the domain admin group isn't a good idea I think ,using NTFS advanced permissions is by far wiser... that said checking for any GP group policy that might exist for that object might be what you are looking for .



    Moderator Note: Removed excessive quote, please refrain from quoting all previous message text.
     
  5. dreec

    dreec Nibble Poster

    59
    0
    19
    Nelix - Try analysing your current security settings with the basic template, this will show you where all of the current settings have been changed, from here you should be able to pick up where the problem is. Not only that if
    "late network admin was employed he put into place some fairly strict permissions on the network, TOO strict to be honest."

    It will also give you a rundown of where probs. may occur in the future

    Just an idea
     
    Certifications: To many to list here, to few to matter
    WIP: None

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.