Results 1 to 4 of 4

Thread: Problem connecting domain directory with global group

  1. #1
    Join Date
    Jun 2009
    Posts
    87

    Problem connecting domain directory with global group

    I have a legal problem on a directory. I created a global group named GG_XP in my area. Inside I added the computer named XP1. I applied this global group to a directory named "Only_my_XP" on my DC1. It is attached to a xcacls of directory "Only_my_XP".
    BUILTINAdministrators (OI) (CI) F
    DEMOGG_XP (OI) (CI) C
    AUTHORITY NTSYSTEM (OI) (CI) F

    It has attached description of the global group
    net group GG_XP /domain
    Group Name GG_XP
    Members -------------------------------------------------------
    XP1$ XP2$ XP3$

    But when I browse the directory "Only_my_XP" from the computer XP1 with a domain user account, I'm denied access.

    I do not understand. The user of premium domain is on the right of the computer. But the domain user can not deny the level of security. Please note that I am using Windows Server 2003.

  2. #2
    Join Date
    Aug 2008
    Posts
    540

    Re: Problem connecting domain directory with global group

    Your group allows computer accounts XP1$ XP2$ XP3$ that connects to the directory? You do not use the computer account but your account area and you'll never have impersonalisation of a computer account. Viewing the effective permissions for your user on the rep.

  3. #3
    Join Date
    Jun 2009
    Posts
    87

    Re: Problem connecting domain directory with global group

    My user has no right to the directory (I have given above a cacls rights), but the computer via a global group. So if I understand correctly, a computer has no interest in the directories or I'm wrong.

    The problem is that I saw someone created GPO to the domain level and not filtered through a WMI but with a global group in which he entered machines ..
    Only one problem is access denied to directory GUID.

  4. #4
    Join Date
    Aug 2008
    Posts
    540

    Re: Problem connecting domain directory with global group

    If a computer can have rights to a rep but must use the account to connect to it (typically when using software running on this account there) but you're logged in with your user and you accede to your rep with account, not the machine account.

    On the GPO so it has nothing to do with directory. You can filter the GPO with groups to prevent security they apply to certain machines, but it's different.

Similar Threads

  1. Add domain user\group to local admin group problem
    By Landon in forum Active Directory
    Replies: 3
    Last Post: 16-10-2009, 09:30 PM
  2. VB. List the userID from group (Domain Admins set as Primary group)
    By epremyan karapet in forum Software Development
    Replies: 1
    Last Post: 12-10-2009, 07:26 PM
  3. Global Group or Universal Group
    By aconti in forum Active Directory
    Replies: 5
    Last Post: 01-09-2009, 10:09 AM
  4. Replies: 2
    Last Post: 01-05-2009, 11:20 PM
  5. Replies: 1
    Last Post: 10-06-2005, 07:52 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,524,416.40980 seconds with 17 queries