Can't move EXISTING computer objects in AD
suddenly our delegated helpdesk folks having problems moving computers 'access denied'. i've verified create, delete, , write attribs has been delegated on affected ou branches group containing of users affected.
with cloned test account in group i can create, delete, , move computer accounts (that create) . there some existing accounts refuse moved short of domain admin.
this working , bit stumped. had 1 case 'protect accidental deletion' flag @ fault - not main culprit idt.
posting in microsoft technet forums.
please check suggestions in thread below see if can helpful in situation:
delegate control of ou
http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f1d6d833-f3d1-4ef9-a717-1f685e99b1a2/#a27472ee-b7a4-4f2c-90c8-2048a98d696b
delegate control move user objects 1 ou ou
http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f6f751fd-1b83-4cb1-a5f5-62a552e7ac36/
have nice day.
regards
kevin
Windows Server > Security
Comments
Post a Comment