This topic has been archived. It cannot be replied.
-
工作学习 / 专业技术讨论 / AD里的delegate control不work了公司里有个AD Security的project,但是delegate control不work:
1. 我自己的account以前在domain admins group,后来我remove it from domain admins group,而且也没有domain level和computers OU的create computers的permission,但是我还是能join computer to domain
2. 新创建的用户如果用标准的delegation of control,join computer to domain就不work,如果加入account operators group就work
3. ethereal trace里samropenuser response是status_access_denied
我应该enable什么logging再继续troubleshooting?
-iamta(iamta);
2007-7-5
{491}
(#3785183@0)
-
network trace is really overkill for this. check your domain controller group policy. In "user rights assignment", there is one entry call "join computer into domain" or so.
-yr2much(此豪哥不是彼豪哥);
2007-7-8
(#3792320@0)
-
network trace是要看看究竟fail在什么地方。但知道是permission问题也没有什么用。最后还是一个MVP指点了一下才搞定。
-iamta(iamta);
2007-7-9
(#3794401@0)