Limit access to DNS & DHCP console via GPO
Hello:
can anyone point me to a site which gives the steps to lock down the mmc snapin for DNS and DHCP?
Thank you
can anyone point me to a site which gives the steps to lock down the mmc snapin for DNS and DHCP?
Thank you
0 Comments
[ + ] Show comments
Answers (1)
Please log in to answer
Posted by:
KennyLiddle
17 years ago
Depending on the level of access granted on the DNS and DHCP server depends on what levels of access you can give when you create your own custom MMC's.
I created my own for DNC and DHCP admins so they could only perform the functions the busines wanted them to do. Its easier to do through GP applying on ly certain rights but as with all Microsoft Products getting down to granular level permission is a nightmare.
I used these articles as a base
http://support.microsoft.com/kb/230263
http://support.microsoft.com/kb/310422
http://www.petri.co.il/create_taskpads_for_ad_operations.htm
The latter site is good.
Now if your planning a centralized deployment of these consoles create afolder in your NETLOGON on your DC place the shortcut to the consoles there and script it with KIX so the required groups can receive the required shorts to the consoles. Oh and place the consoles in windows\system32 so you can manage them more effectively.
If you need any further help email me at ken.liddle@aah.co.uk.
DHCP permissions If I remember are granted via DHCP server.
I created my own for DNC and DHCP admins so they could only perform the functions the busines wanted them to do. Its easier to do through GP applying on ly certain rights but as with all Microsoft Products getting down to granular level permission is a nightmare.
I used these articles as a base
http://support.microsoft.com/kb/230263
http://support.microsoft.com/kb/310422
http://www.petri.co.il/create_taskpads_for_ad_operations.htm
The latter site is good.
Now if your planning a centralized deployment of these consoles create afolder in your NETLOGON on your DC place the shortcut to the consoles there and script it with KIX so the required groups can receive the required shorts to the consoles. Oh and place the consoles in windows\system32 so you can manage them more effectively.
If you need any further help email me at ken.liddle@aah.co.uk.
DHCP permissions If I remember are granted via DHCP server.
Rating comments in this legacy AppDeploy message board thread won't reorder them,
so that the conversation will remain readable.
so that the conversation will remain readable.