[Samba] Home directory of AD-User

Luca Olivetti luca at wetron.es
Tue Apr 12 07:51:42 UTC 2016


El 12/04/16 a les 09:23, Luca Bertoncello ha escrit:

> Do you mean, that I need to create a group for example "CCHAdmins" and
> add the users to this group? How can I define this group as
> "administrator group"?

Yes, I think so. This is what I tried while testing *but* I still don't 
have samba as an AD controller in production so take the following notes 
with a grain of salt (besides, they are "reverse translated" so the 
terminology could be wrong):


- I want these users to manage printers, so, on the member server that 
manages printing

    net rpc rights grant 'DOMAIN\supergroup' SePrintOperatorPrivilege -U 
'DOMAIN\Administrator'


In order to delegate domain control to this group

- in ADUC I put this group in DnsAdmins (so it can manipulate dns)

- in ADUC delegate everything with the wizard "Create a custom task" -> 
"This folder and contained objects...", select "General", "Property 
specific", "Create or delete..." and "Total control"

- in GPMC put the group in the delegation tab of the domain and of the 
group policy object


Bye
-- 
Luca Olivetti
Wetron Automation Technology http://www.wetron.es/
Tel. +34 93 5883004 (Ext.3010)  Fax +34 93 5883007



More information about the samba mailing list