Recommended Posts

Hello all,

 

Here is the situation: We have a Windows 2012 server running Active Directory, which manages the logins for all of our network resources. So far, whenever a new user needs to be added, one of the office staff has to talk to us techies and ask us to add the user(s) for them. We have agreed it would be more convenient for everyone if they had the option to add users themselves. However, we do not want to give the staff the ability to manage EVERY aspect of the server, which is what would happen if we simply made them admins.

 

From what I understand, what we want to do is give these users Remote Desktop access, and then give them fine-grained permissions so that they can manage AD, and only AD. However, I have tried Googling this whole matter, and maybe I am just using the wrong keywords, but I can't find anything that tells me how to do this*. Can someone help me? Alternatively, if this is not how it is done, or if there is a better way, what would it be?

 

*I'm having trouble with the fine-grained permissions part. I have no issue giving staff remote access

 

Thanks for any advice!

Thank you, I will definitely check out the documentation on delegating AD authority.

 

The issue with RSAT that I see: All our windows computers are Windows 7, while our Server runs Windows 2012. From what I understand, this means the RSAT client for Windows 7 will not work with Server 2012, only 2008. Correct?

 

If so, this will still be fine through remote desktop, right?

 

Re: MMC Snap-Ins. Is that a different method entirely, or is it related to something already mentioned, like RSAT?

You could write powershell scripts so those users would only have to enter a username, password and group (group could be 'automated', so people can only add others to their own group)

 

Also MMC snapin, win+r mmc. You can access AD and such like it where local.

  On 06/06/2014 at 17:53, Seizure1990 said:

Thank you, I will definitely check out the documentation on delegating AD authority.

 

The issue with RSAT that I see: All our windows computers are Windows 7, while our Server runs Windows 2012. From what I understand, this means the RSAT client for Windows 7 will not work with Server 2012, only 2008. Correct?

 

If so, this will still be fine through remote desktop, right?

 

Re: MMC Snap-Ins. Is that a different method entirely, or is it related to something already mentioned, like RSAT?

 

If you install RSAT for Windows 7, it should let you manage a 2012 Active Directory without issue.

 

All the Active Directory management tools are snap-ins for MMC, which is the Microsoft Management Console. RSAT will just add the necessary snap-ins and shortcuts for you to the Administrative Tools option in Control Panel.

 

Under no circumstance should you let a user anywhere near the server desktop. It's for IT people only.

Letting departments add users on the fly without it consent or questioning...where do I sign up....let me make 1000 different accounts so that I can gain access to the network.  Hell if someone pays me off I will give them access to whatever they want.  f IT.

 

 

 

Seriously, is this the best course of action?  You will have no control over your environment by allowing departments create accounts.  This is a big no no.  You should have a bigger IT department then to be able to handle add requests. 

  On 06/06/2014 at 18:44, sc302 said:

Letting departments add users on the fly without it consent or questioning...where do I sign up....let me make 1000 different accounts so that I can gain access to the network.  Hell if someone pays me off I will give them access to whatever they want.  f IT.

 

 

 

Seriously, is this the best course of action?  You will have no control over your environment by allowing departments create accounts.  This is a big no no.  You should have a bigger IT department then to be able to handle add requests. 

A) It isn't the whole department, just a couple administrative staff.

 

B) We are a global non-profit, and this is the budget we work with. No full time tech staff (I work as a consultant for them, and show up for 3 to 6 hours a week. Yes, the amount of resources we have is minimal, but it's what we work with.) It was specifically requested that there should be a way for the organization admins to add new staff so they can access the network resources. I don't think that this will end up badly, everyone here is part of this organization because they believe in their work, not for the pay.

 

Anyways, the main point is I'm just carrying out orders, and this is what I was asked to do.

Fair point. Is there a way to set it up so that they can only create users within a certain group? This would actually be preferable, since we have custom user groups and we want all new users to be put into the basic one.

 

Even if there isn't a way though, I don't think this is a serious issue. The staff who will be given the ability to do this are very high up in the organization. They would essentially be f'ing up their own org... and if that's what they choose to do, their business, not mine. I just get payed by the hour to set all this up and fix their issues.

Ok... when I download the RSAT installer, I get an error: "The update is not applicable to your computer"

http://www.microsoft.com/en-us/download/details.aspx?id=7887

 

I made sure to get the x64 bit one. What is the problem? Did I use the right download?

What I would suggest is just do this via web, something like the manage engine AD manager, has help desk delegation where users can be given rights to create/delete/unlock/reset password, etc..

 

There is a free version, since you mention this is a nonprofit I would think you have a pretty small setup and the free should work

 

http://www.manageengine.com/products/ad-manager/

 

This way nothing to install on any user machine..  And just hit a webpage, click a few things - this much easier to understand for non AD admins, etc.

 

I am not sure if the free version allows for help desk users?  Do you have more than 100 users in the domain?  Or plans to go over that?  You could always contact them for nonprofit pricing options, etc.. that might fall to your limited budget?

 

Another option in this line would be

http://www.omniecontrol.com/

 

Their pricing model is based on user..  Gov is like $4 a user..

This topic is now closed to further replies.
  • Posts

    • Helldivers 2 announced for Xbox, finally ditching PlayStation console exclusivity by Pulasthi Ariyasinghe In a surprise announcement, a massive PlayStation console exclusive has been announced for Xbox consoles. Over two years after launching, Helldivers 2 has now been confirmed for Xbox, and pre-orders are already live. Catch the brand-new platform announcement trailer above. "A new dawn is upon us. Super Earth is expanding its operations and opening new enlistment centres," says the announcement on Helldivers' social media channels today. "Xbox players, your opportunity to enlist is coming when HELLDIVERS 2 deploys to Xbox Series X|S." Developed by Arrowhead Game Studios, the studio behind Magicka, Helldivers 2 comes in as a third-person shooter experience focused on cooperative play. Set in a future society, players take the role of shock troops going across the galaxy to defend humanity against aliens, robots, and other threats as well as 'spread democracy.' “We know gamers have been asking for this for some time and we are so excited to bring more Helldivers into our game," says Helldivers 2 Game Director Mikael Eriksson. "We have so much more in store for the future months and years – and the more players we have the more stories we can tell! The fight for Super Earth has only just begun." Helldivers 2 on Xbox Series X|S will be released on August 26. Both the Standard Edition and Super Citizen Edition versions are now available for pre-order, costing $39.99 and $59.99, respectively. Crossplay has also been confirmed as a feature, connecting Xbox with PlayStation and PC players.
    • I'd probably use the word consistent instead of reliable. It isn't that games crash more on Windows 11 (short of the NVidia driver issues, but you can't really blame Windows for that). It is true that Windows 10 produces more consistent benchmarks, which would translate into a smoother gaming experience. Windows 11 requires more customization to make in a "clean" test system. Also, you're likely not wrong that 25H2 will be the last version before Windows 12, but there will likely be Windows 11 version releases after Windows 12 comes out. Keep in mind that Windows 10 got both 21H2 and 22H2 after Windows 11 came out, I don't see why Windows 12 would be any different. Maybe Microsoft will be comfortable shutting Windows 11 development down sooner if Windows 12 doesn't have the same kind of spike in hardware requirements that 11 did, but this is all just speculation, we will have to wait and see what happens.
    • Google open-sources zero-knowledge proof code for enhanced online privacy by Paul Hill When you go out to a physical store and attempt to buy alcohol or cigarettes, you’ll get asked to show some ID; online, when you want to visit adult sites, you don’t currently need to prove your age, but lawmakers in various countries are looking to change this. One technology that has been developed to address the age checks needed is Zero-Knowledge Proof, where you prove your age without having to reveal other data like birth date or ID. To help companies develop their own Zero-Knowledge Proof (ZKP) technologies, Google has released its ZKP libraries as open-source, meaning they can be taken and used in other projects or adapted. This will make it easier for third-party developers to create privacy-enhancing age verification applications. We heard a bit about ZKP from Google earlier this year when the company said that it was integrating the technology into Google Wallet to help disconnect your age from your identity. It also said at the time that it would be using it in other Google products and partner with apps like Bumble to help with verification. It also said at the time that it would open-source ZKP; that promise has now been fulfilled. As libraries, Google’s newly open-sourced software can be integrated into a whole range of applications. As mentioned, Google is using it in Google Wallet, and it could also be used to verify the age of people visiting adult websites without needing to reveal their identity as part of the verification process. Google has also said that the European Union’s eIDAS regulation encourages EU member states to integrate technologies like ZKP into the European Digital Identity Wallet (EUDI Wallet). The open-sourcing of ZKP could help with the acceleration of the development of these EUDI Wallets. The open-sourcing of the ZKP libraries by Google will benefit various groups of people. We’ve mentioned that developers will benefit as they can use the libraries in a variety of apps. Businesses will also benefit by being able to meet privacy needs more easily. Another group to benefit will be researchers who can use this “more efficient and performant ZKP implementation” to help create new applications and uses of technology. Finally, users will benefit from more private and secure digital ecosystems. Now it remains to be seen how much adoption these ZKP libraries will get, given the growing need for such technology. Image via Depositphotos.com
    • I Have a batch file that opens 2 websites dealing with money. I want to add to it with the first step to remind me to start a vpn extension that I use with chrome.  If  it is easier to use powershell that is fine too.  thx   Hope this is enough info.
  • Recent Achievements

    • Week One Done
      956400 earned a badge
      Week One Done
    • First Post
      loose_observer earned a badge
      First Post
    • Week One Done
      BeeJay_Balu earned a badge
      Week One Done
    • Week One Done
      filminutz earned a badge
      Week One Done
    • Reacting Well
      SteveJaye earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      446
    2. 2
      ATLien_0
      158
    3. 3
      +FloatingFatMan
      150
    4. 4
      Nick H.
      65
    5. 5
      +thexfile
      62
  • Tell a friend

    Love Neowin? Tell a friend!