How to manage specific workstations in domain

We have one domain with several sites and use a separate IP subnet for each. We would like to allow a "superuser" at each site to manage their servers/workstations as an administrator but only for the computers at their site not throughout the
rest of the domain. What is the recommended way of doing this?

1. Create an OU for each site. Place the servers and/or workstations for each site in the corresponding OU. Be aware of policy inheritance.
2. Create a domain local security group for each site, for instance "NYCAdmins, BejingAdmins" etc.
3. Create secondary (administrative) accounts for the site admins
4. create a group policy object for each site and link it to corresponding OU created previously
5. for each GPO navigate to user configuration \ preferences \ control panel settings \ local users and groups
6. create new local group, action update, group name administrators. Click add and browse to the secondary account for the admin for that site. action: add to this group.
Kind regards, Vincent

Similar Messages

  • How to manage endpoint protection on Domain Controllers?

    I am using System Center 2012 but I chose not to install the client on my DC.  However I wanted to install SC Endpoint Protection so I installed it manually and painstakingly added all the recomended DC, DHCP and DNS exclusion (from the provided template). 
    First, am I making the correct assumption that I cannot manage endpoint protection on the DCs from the SC server without the SC client installed on the DCs? Second, what is the best way to manage endpoint Protection on DCs?
    Thanks
    me

    Hi,
    For Configuration Manager 2012 / Enpoint protection 2012 the templates are builitin to the product, In the Admin Console under Antimalware Policies, right-click and select import, there you will find all templates, one is called FEP_Default_DC which is the
    default template for a Domain Controller...
    regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • My family put multiple devices on the icloud, and I need to know how to manage duplicate entries.  Specifically contacts.  If I fix the contact list on my pc will it push the info out to the other devices and maintain it correctly?

    My family put multiple devices on the icloud, and I need to know how to manage duplicate entries.  Specifically contacts.  If I fix the contact list on my pc will it push the info out to the other devices and maintain it correctly?

    All devices signed into the same iCloud account will finish up with the same contacts. Of course if prior to joining iCloud two family members each had an entry for Uncle Fred, then you will finish up with two contact cards for Uncle Fred, and so on. If you tidy this up on your computer then the changes will propagate to everyone else.

  • How to manage one domain from another domain

    I have created 2 domains domain1 and domain2. I deployed a web application in domain2 and created a managed server "newManagedserver-1" to run the application. From admin console of domain1, I need to control ie start/stop managed server "newManagedserver-1" created in domain2 by using the Node manager.
    Please let me know if its possible and if so, please let me know the steps.

    855557 wrote:
    Ok thanks for information. I have following questions:
    1)Is it possible for same domain to exist on more than 1 physical machine. I mean lets consider I create a domain domain1 in physical machine1 and same domain1 in physical machine2. Can I monitor managed servers of physical machine2 from admin console of physical machine1. Paths of the domain1 on both the physical machines being same(C:\bea\user_projects\domains)
    2)If the paths of domain1 on both physical machines is different(for eg C:\CLOSR\install1\appserver\autodeploy\domain1 and C:\CLOSR\install2\appserver\autodeploy\domain1), then will the node manager functionality with admin server of machine1 and managed servers on machine2 work?---We can create one domain (domain1) and have different managed servers on two different physical machines.
    Which means create a domain on machine1,and while adding a managed servers to that domain,
    1)create 1 managed server (MS1) and provide the IP address of the same box(machine1)
    2)create second managed server (MS2) and provide the IP address of the second box(machine2)
    In this way we can create two managed servers on two different machines (machine1 and machine2), and as per your requirement monitor/manage the managed servers from machine1.
    We don’t need to create a domain on another machine explicitly,however this configuration need few steps to be performed.
    This concept is called Horizontal cluster,Following forum link will explain the same in detail.
    Vertical and Horizontal Clustering
    ---Regarding having different paths for the same domain on machine1 and machine2,
    We will not create a domain on machine 2 explicitly; the concept is creating one domain but distributing it on different machines.
    So paths of the installation or the directory where we have the managed sever will not matter here.
    The node manager functionality will work, provided we configure it correctly.
    Following link will help you understand this in a better way.
    http://download.oracle.com/docs/cd/E13222_01/wls/docs90/server_start/nodemgr.html
    If you need the guidelines in node manager configuration (bit tricky) please let me know.
    Edited by: user123456 on May 2, 2011 9:32 PM

  • How to Manage Creative Cloud for Teams | Learn Creative Cloud | Adobe TV

    This is a short video about how to manage and administer Creative Cloud for teams using a new, intuitive web-based tool called the VIP Admin Console. The Admin Console allows IT administrators to add Creative Cloud seats, assign or re-assign these seats to team members, monitor storage allocation and more. This short video shows you how this is done.  
    http://adobe.ly/ZDWoCl

    Can I assign more than one seat to a user?
    In our studio we have 7 workstations - so far we just had 7 CSs in Volume Licensing. We have licenses assigned to machines rather than people - any of the artists can sit on an available machine and just start working.
    What is the equivalent for CC?
    Do I create a single Adobe ID for our studio and assign 7 seats to this user and then use it on all machines for installations, or do I have to create 7 Adobe IDs (one per workstation) and assign a single seat to each of them?

  • How can I list all the domains configured for Weblogic Servers?

    How can I list all the domains configured for Weblogic Servers?
    I saw a note, which says the following:
    "WebLogic Server does not support multi-domain interaction using either the Administration Console, the weblogic.Admin utility, or WebLogic Ant tasks. This restriction does not, however, explicitly preclude a user written Java application from accessing multiple domains simultaneously."
    In my case, I just want to list all the domains, is that possible by using any scripts?
    Thanks
    AJ

    If you use WLS Node Manager and the Config Wizard was used to create the domains, then the list of domains should be in a location like this:
    <MIDDLEWARE_HOME>\wlserver_10.3\common\nodemanager\nodemanager.domains
    Enterprise Manager Grid Control also has support for multi-domain management of WLS in a console.

  • How do I restrict access by domain and the rest of the world to the documents in the public_html folder in iPlanet Portal Server?

    Hello,
    We have multiple domains configured in our iPlanet Portal Server 3 demo environment. In addition we are using the gateway.
    In one of these domains the userTemplate.html file is tailored to display Macromedia Flash components at dynamic positions on the page. The logical home for these Flash components (since the portal software cannot find them if we simply store them in iwtDesktop) is somewhere below the /opt/SUNWips/public_html directory.
    The problem is that once the file is stored here I can access it if I know the url (http://server:8080/file_path) without being authenticated in the domain.
    The allow/deny url policy settings are specific to a domain and seem to have no affect on the rest of the world.
    Any advice you can provide is greatly appreciated.
    Thanks!

    Joel,
    If your intent is to block access to the doc root, you can probably use access control lists (acl) to prevent anyone from accessing the files stored under public_html. You can get more information about how to create ACLs from the following URL
    http://docs.iplanet.com/docs/manuals/enterprise/41/ag/esaccess.htm#1005439
    You can even set up Basic Authentication for access to the direcory or ip based access or any which way you want. I've personally never blocked access to the doc root in portal, so I am not sure what the impact will be.
    Hope this helps!

  • How to Publish Multiple Websites Using Domain Masking

    Let's say I have a mobileme acct called applesoranges, but then I decided not to use this name for my website. Using iweb, I have created a different website called blueberry.com, and was able to figure out how to set up my personal domain and then mask appleoranges so that only blueberry.co, appears.
    I now want to add another website called strawberry.com. With one mobileme acct (applesoranges), is it possible to host 2 separate websites, each of which is masking the original mobileme acct? How does one set up 2 separate websites using iweb (each masking the original acct name)?
    Many thanks!

    For every MobileMe account you can only use the personal domain name option and CNAME only once. You enter your first domain name into your MMe account and then go and set up CNAME forwarding at your domain registrar to forward to web.me.com. For any other sites that you create, you need to go to web forwarding. You set-up the other domain names by using masked web forwarding and point them to web.me.com/username/sitename and by masking these will just show your domain name address and not your MobileMe/iWeb url.
    Make sure that you separate out your sites, as it will be easier. You can either duplicate the domain.sites files and have one site per a domain file or use a program called iWebSites to help you manage multiple sites.
    You also have the option of not using MMe and you can publish to a folder instead and upload directly to each domain hosting space. This gets away from the problem of how to forward sites to iWeb/MMe.

  • I still can't figure out how to manage & sync my medias.

    Hi everyone
    I have to admit, I've owned an Iphone for 2 years now and I still can't figure out how to manage my pictures. I'm confused, I don't know how to get them out, import them...I have 3 albums in my phone taking a huge amount of space with duplicates in : camera roll, photo library , last importation ...!
    same goes for Adress book.
    Can anybody help and explain to me how that works ? Explain it to me as if I'm a 4 year old !
    Here are some specific questions :
    where are the pictures saved on the macbook ?
    how to manage and delete them in batch ?
    how to keep one folder in the phone ?
    How does this Syncing business work?
    Thanks for your help
    D

    Is this article of any help http://support.apple.com/kb/HT4236 ?

  • Can i use single node manager with two weblogic domain?

    I am very new to weblogic and node manager.
    i had created two domains in weblogic. (single node manger).
    Can i connect both domains with same nodemanger?
    How to do this?

    The node manager uses a nodemanager.domains file to determine which domains it manages, for example,
    domain_name=/path_to_domain/domain_name
    other_domain_name=/path_to_other_domain/other_domain_name
    This file can be found in the NODEMANAGER_HOME, that you specified when starting the node manager (startNodeManager - NODEMGR_HOME="${WL_HOME}/../oracle_common/common/nodemanager")
    When you are running the domain on multiple machines you have to enroll the node manager into the domain (http://docs.oracle.com/cd/E23943_01/web.1111/e13813/reference.htm#i1065827)
    A scripted example can be found here: Middleware Snippets: Automate WebLogic Installation and Configuration. The Node Manager administration guide can be found here: Oracle&amp;reg; Fusion Middleware Node Manager Administrator's Guide for Oracle WebLogic Server 11g Release 1 (10.3.6) -….

  • How to Manage Text In PDF

    Hi everyone.
    I am pretty new to PDF programming world and for study PDF ,I am prefering PDF specification.
    I can manage Printing text on my page but when my text length goes out to the page range it get crop
    ..so my requirement is how to justified that text line on next line
    please suggest how to manage this problem.
    currently I am tackling this prob by
    T*[()] TJ
    but I have to do it manually..
    thanks in advance.

    You have to do this manually. That is just one reason why it's in general a
    bad idea to create PDF files from scratch: You have to process all the font
    metrics yourself and find out how wide your text will be, and then position
    it accordingly on the page. When you use a PDF library or framework, that
    is usually done for you (or at least there are ways to get to that
    information in a much more user/programmer friendly way).
    Karl Heinz Kremer
    PDF Acrobatics Without a Net
    [email protected]
    http://www.khkonsulting.com

  • How to start / stop nodes without domain-controller / automatically on Win?

    Hi,
    we have a distributed installation of CMSDK 9.0.4.
    We have installed a 9.2.0.4 Database on Solaris and we are using the 10g(9.0.4) Infrastructure on Solaris with it.
    The first installation of CMSDK uses a J2EE-MidTier installation on the Solaris server and contains the CMSDK domain controller and a normal node with nfs protocol server running.
    The other installations are done on Win2003 Blades. Currently we are using two Blades. On each there is a J2EE-MidTier installation and within these we have installed CMSDK with HTTP-Node and normal node. We are using NTFS-Server within the normal nodes.
    The Blades are within one Domain and we have NLB-Cluster activated for both.
    The whole thing sounds complex, but it works fine. We only have some trouble regarding start/stop of the nodes:
    1. If the solaris backend fails, our cluster-configuration tries to stop and start cmsdk. While stopping cmsdk, all nodes - even those on the Win-Servers - are stopped. But starting does not bring em up again automatically.
    2. If a Windows Server is booted, the normal node does not start automatically.
    3. If one Windows Server is not available, the ifsctl check takes a very long time because it's trying to get information from the missing one.
    Is there a way to restart the domain controller and node on solaris without stopping the nodes on Windows?
    How can we start the windows nodes automatically after reboot?
    Is there a way to probably start the nodes without being managed / guarded by the domain controller?
    Thanks for help,
    Alex

    Try adding this script to your /etc/init.d directory:
    #!/bin/sh
    ifsctl start << EOF
    <ifsctl password>
    EOF
    Replace <ifsctl password> with the password that you would give at the prompt.
    It will complain about Inappropriate ioctl for device, but it works.

  • [Forum FAQ] How to sync time with a Domain Controller for a standalone server

    As we all known, if a computer belongs to an Active Directory domain, it will sync the time automatically by using the Windows Time service that is available on Domain Controllers.
    While a standalone server will synchronize with its local hardware time and Windows time server. (Figure 1)
    Figure 1.
    Under some circumstances, a standalone server is necessary in a product environment. We can sync the time of this standalone server with the Domain Controller using
    the steps below:
    1. Modified the value of the AnnounceFlags:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config
    Under this entry we can see the default value of AnnounceFlags is 10 (Decimal), we configure the value as 5 (Decimal). (Figure 2)
    Figure 2.
    2. Confirm the value of the registry key below is set to 0:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\NtpServer 
    Figure 3.
    3. Configure the standalone server to synchronize with a specific time source (Domain Controller).
    In our test, we configured our Domain Controller (192.168.10.200) as the time source. Used the following commands:
    w32tm /config /syncfromflags:manual /manualpeerlist:192.168.10.200
    4. Sync the time with the Domain Controller using the command below:
    w32tm /config /update
    From the figure below (Figure 4), you can see the after we did all the steps above, the time on the standalone server was synced with the Domain Controller.
    Figure 4.
    (Note: Peerlist is a separated list of DNS servers, or IP Addresses for the time servers)
    More information:
    Windows Time Service Tools and Settings
    http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx#w2k3tr_times_tools_dyax
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    Thank you for the instruction! I am sure it is one of the scenarios that majority of administrators will run into. So I suggest to write a wiki about it and publish it for this month's TechNet Guru in Windows Server section. This month's TechNet Guru can
    be found here:
    Calling All Wise Men! Windows
    Server Gurus Needed! Apply Within! No One Turned Away!
    Thanks for your informative post. :)
    Regards.
    Mahdi Tehrani   |  
      |  
    www.mahditehrani.ir
    Please click on Propose As Answer or to mark this post as
    and helpful for other people.
    This posting is provided AS-IS with no warranties, and confers no rights.
    How to query members of 'Local Administrators' group in all computers?

  • Manage client in parent domain from child domain

    My site has a root domain (mydomain.net) and a parent domain (ent.mydomain.net).
    My primary SCCM site is installed in ent.mydomain.net and is managing all my clients.
    I have 4 DC's installed in mydomain.net that I would like to manage from my child domain (ent.mydomain.net).
    It is my understanding that if the schema has been extended in the parent domain, and I manually install the client on the DC, it should be able to be managed from the child domain.  
    I have installed the client in the parent, but it cannot find the site in the child (I have not extended the schema yet).  i know that the client will not be able to find the site until the system management container has been created and populated
    (does not currently exist).  I know that I can create the container, but how would it get populated with the correct site information.  
    If anyone has any experience with this kind of configuration, the help would be appreciated.
    Thanks

     i know that the client will not be able to find the site until the system management container has been created and populated (does not currently exist).  I know that I can create the container, but how would it get populated with the
    correct site information.  
    You could enable AD publishing to that domain, but site assignment is also a matter of site assignment boundary groups. You can also assign a client to a site manually though.
    Torsten Meringer | http://www.mssccmfaq.de

  • How many managed Servers do you need?

    Hi,
    One thing that has come up time and time again, is when trying to think about a new project and a new WL domain, is trying to know how many WL Managed Servers do you need?
    Does BEA have some sort of metrics which says ok for this amount of input we recommend you having 4 managed servers on 4 single boxes?
    And is there think on have 2 managed servers on 1 box or 2 managed servers on two boxes?
    Any Help Appreciated.
    Kind Regards,
    Alistair.

    Hi :-D
    I don't believe BEA have guide lines on how many Managed servers are required based on Metrics. You could look at some performance evaluations but it's really only relevant if your application acts in the same way.
    Cheers,
    Doug.

Maybe you are looking for

  • OAS 4.0.8.1/Redhat 6.2? WRKSF problem

    Hi, I've installed OAS 4.0.8.1 on Redhat 6.2 but when I start the processes up the WRKSF goes down after a few seconds, I've seen a previous posting on this subject had a workaround proposed by Dennis Irwin which seemed to work for many people, unfor

  • Reprint Vendor Withholding Tax Certificates

    Hi, Iam doing the changes to Rprint Vendor withholding tax certificate J_1IEWT_CERT_REPRINT. But it showing different line items compared to Certificate J_1IEWT_CERT. Fiscal year is different in Certificate and Reprint Certificate. When fiscal year c

  • Server 2012 VMs hosted on 2012 R2 Hyper-V fail to update, all other OS VMs are fine

    Host: 2012 R2 VMs: 2008 R2, 2012, 2012 R2 Systems has been running fine until I decided to update my VMs a few days ago with the Dec 10th updates.  2008 R2 VMs update no problem, 2012 R2 VMs update no problem, but 2012 VMs fail to update.  I spent 7

  • Anyone got the SimpleCertAuthenticator example working with 5.1??

    The SimpleCertAuthenticator example that does the client certificate to user mapping doesn't seem to work. I followed the instructions and tried many times without luck. Any comments? Like where to look for error messages? Thanks. Honbo

  • VGA P20 - 552 (vertical lines)

    Hi i need big help i am having problem in my VGA when i start it shows vertical lines then when it boots to OS the screen becomes black i had tried to use system restore it did work after a reboot then i rebooted the problem started again it since th