Rights to enroll computeur on domain 2008 Server

Hello,
How are you ?
I'm sorry if my English isn't very well...
So... I've got few servers on Windows 2008 R2.
I search to limite rights on my domain.
Is it possible to make a security group or a GPO to limit a part of account to enroll computers ?
I don't whant use the operator account group because it gives to more rights.
Thank you for your help
Fred

On Thu, 19 Feb 2015 06:08:06 +0000, djram82000 wrote:
Why complicate while there has delegations.I'm going to try this quickly.Thank you !
https://morgansimonsen.wordpress.com/2013/12/17/delegating-computer-object-management-tasks/
Great article on delegating the management of computer objects.
Paul Adare - FIM CM MVP
That's like building a fire escape out of balsa-wood and painting it with
thermite. -- Peter da Silva on writing scripts in csh
Hello,
Thank you for the link.

Similar Messages

  • Unable to join to domain 2008 server core machine

    Hi, I'm trying to join the server core computer to domain. When I'm running command: netdom join core /domain:contoso.prv  I'm getting error:
    "the specified domain either does not exist or could not be contacted"
    after command : netdom join core.contoso.prv /domain:contoso.prv
    error:
    "The RPC server is unavailable"
    I can join full version of Windows Server 2008 with GIU
    When trying to ping my server core machine form DC- doesn't work. Pinging DC form server core is working.
    My domain it was just configured and is fresh installation. Do I have to change some firewall settings on core to join to the domain..
    I do not understand the problem.
    I just learning, so please to be placable, pelase. 

    I Have resolved the problem. I have not noticed
    (I do not know why) the IP of the core server
    is form APIPA  range. I thought that I
    changed it. After the change everything works
    fine :). Thanks for help anyway.

  • Domain controller 2008 Server with SP2

    Here is a real issue which i cannot track down what is causing it.
    It appears that in windows 2008 Server running DHCP, DNS and AD i am getting some weird errors on the clients.
    The client machines are all Windows 7 Professional x64.
    The Issue is that the Domain controller seems to disappear as the logon server from the client after a few days. On some it indicates that there was no logon server available, but still logs in.. Which should be impossible since i have group policy configured
    to block the ability of logon without a logon server.
    The issue with this, is that over time, the desktops seem to go rogue, they no longer populate the information as to password expiration, and at times don't allow the clients to access the network shares.
    The security log, shows hit and miss as to if it sees them log into the domain.
    the weird issue is that if you log out, switch user, and change the users password, then log back into the desktop with domain\username and a new password the issue goes away for about 10 days.. then re-appears and causes all sorts of fun issues on the domain.
    I took another step and decided that i would give a shot to building a clone test network, using a cloned image of the Domain controller, and it doesn't seem to happen on that side..The test network just has less PC's but they are all the same hardware..
    Here is what i have troubleshot so far:
    DNS looks fine.. no errors or issues..
    DHCP looks fine, no duplicates etc..
    AD has all the information correctly, and the security log looks fine, most of the time..
    Windows updates are all up to date
    All desktops have logon scripts, but i have removed the cached data from the management console (Cred manager)
    Modified Group policy and forced it across the network.. Can see the GPResult from the clients and they have the updated settings, but the clients don't seem to care..
    Group policy is set to wait till network comes up and require a domain controller to log into the client desktop.. This sometimes works, sometimes does not, it was done to see if the problem was happening on other machines, there are about 15 total out of
    47 currently having the issue.
    All the desktops are fresh installs, not ghosted images, not clones, or something you would need to sysprep.
    Thoughts?
    Rob

    Hello,
    please post an unedited ipconfig /all from the DC/DNS servers and a client with the problems.
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • Leopard to 2008 Server domain

    I have a 2008 Server with XP clients. The XP clients are working with no problems.
    But the leopard macs don't add to domain. I use directory Utility on Leopard. But the client says: "Unable to add the domain. There was no response from jstech.local. Please check that the address you entered is correct." What is wrong?

    I had this problem a while back, I did manage to get the Windows 7 machine to join the domain. After I re-booted I was not able to logon to the domain from the Windows 7 machine.
    See this link below
    http://discussions.info.apple.com/thread.jspa?threadID=2200942&tstart=0&messageI D=11230874

  • Windows 2008 server OS authenticated user keeps failing

    I have a new server that has windows 2008 server installed, 64-bit. I've installed oracle 11gR2 64-bit and have created my database. Now I need to create two oracle accounts that are OS authenticated and I can't seem to get this right. I've set os_authent_prefix in my spfile and I've created the user (example) OS$<domain>\<username> in the database. In Windows, the account name equals <username> and that account belongs to Administrators and ora_dba groups. I've tried creating the oracle user with <domain> in caps and lowercase, but both fail. On the server, the domain is all lower case.
    So in SQL> create user "OS$my.domain.mil\user1" identified externally; (user created)
    Grant connect to "OS$my.domain.mil\user1";
    Log out of sqlplus, pull up command prompt in Windows 2008 server as 'user1' and type in "sqlplus /"
    Invalid username or password.
    What am I missing here? Any help appreciated.
    SA feedback: "Finally, Windows Server 2008 R2 Operating System has a tighter security scheme than that of previous Windows OS.
    Also, it would be helpful if I remove the AD domain controller role from this server. This may require reinstallation of this server (worst case). Let me know when I can do this so you can proceed with your configuration."
    Edited by: wolfeet on Jun 21, 2011 5:02 PM

    Hello Ricardo,
    You may want to reference SAP Note 1054740 - SAP System Installation on Windows Server 2008
    and ensure you are on SAP Netweaver 7.0 SR3 or above, and it will also tell you if the product you are installing is supported in Windows 2008 Server.
    For database and SAP product combinations that are already
    supported by SAP to run on Windows Server 2008, see the Product
    Availability Matrix at: http://service.sap.com/pam
    Also check the following: in Regedit.
    SYSTEM\CurrentControlSet\Services\gpsvc
    Right click on it and select "Permissions" in the context menu.
    Provide "Full Control" for sidadm
    Does the installation user has full administrative rights and belongs
    to the group of LocalAdministrators and to Global Administrators also
    when you are doing a domain installation ?
    Please ensure the user <sid>adm has the access rights
    to change the file system permission.
    Regards,
    Paul

  • Install question - 11g on 2008 server

    Hello All,
    I am knowledgeable in installing Oracle on Linux. Now I am tasked to install 11g (11.1.0.7, 64 bit )on windows 2008 64 bit. In Linux, I manually create my oinstall and dba group as well as the oraadmin account and oracle account. Is this a similar process on windows 2008 server? Also, should I join the host to the domain, or leave it out of the domain? is it that simple, that you just log into the windows server with an account that has administrator right and just run setup.exe? Will the oracle installer create these groups for you? And last, if I do join the host to the domain, should I use a domain admin type account?
    This will be installed on a Dell server with 1.2 TB (RAID 5). yes, one large drive, but will be partitioned as drives d,e,f and g. Any tuning tips would be appreciated..
    Thanks all..
    Rob

    http://download.oracle.com/docs/cd/B28359_01/install.111/b32006/toc.htm
    This documentation should answer all your questions. And, on a side note, it is a lot easier to install Oracle on Windows compared to Unix/Linux and no, I am not saying installation on Unix/Linux is difficult :-)

  • Error connecting to the SAP SRV on Windows 2008 Server platform

    Hi All
    We have a problem with one of our clients they bought a new sbs windows server 2008 and we loaded sql 2005 and sap b1 SP01 PL07.
    When we did the SBO install we experience connection issues and we created odbc connection on the server using named pipes and tcp/ip (used both server name and Ip address).
    We also configured the server in configuration manager and we managed to login and solved the slow system connection issue. We also created odbc connection on the client machines. (Machine are on a workgroup and users have administration access on all machines),we also installed native client on all machines.
    After the first batch of client installs we managed to have connection, they were other computers which were left out during the first client install and now the client want to do the remaining machines connected to SBO. On every machine that we install now we get the same error :-
    *Connection failed:
    SQLState:'08001'
    SQl Server error:10060
    [Microsoft][SQL Native Client] TCP Provider: A connection attempt failed because the connected party didnot properly repsond after a period of time, or established connection failed because connected host has failed to respond.
    Connectioin failed:
    SQLState:'HYT00'
    SQL Server Error:0
    [Microsoft][SQL Native Client]Login timeout expired
    Connection failed:
    SQLState:'08001'
    SQL Server Error: 10060
    [Microsoft][SQL Native client] An error has occurred while establishing a connection to the server. When connecting to the sql server 2005, this failure may be cause by the that*
    Please help as most user who need access can't login and they are the main users.
    rgds,
    Bongani Dlamini

    Hi Eric,
    yes we are using Windows 2008 SBS for the SAP EHP4 FOR SAP ERP 6.0/NW7.01 installation.
    we tried to create the key but it says access is denied.
    Actual thing is we got the server with Windows 2008 server 64 bit SBS (standard FE) with Domain Controller (DC) configuration.
    We have removed the DC using dcpromo to convert into Wokgroup and tried the SAP installation.
    I hope you got the idea and please let me know any further suggestions or it is the problem with the license.
    Thanks & Regards,
    Prabhu Reddy.

  • How can I set up printing to queues on a Windows 2008 server directly from the iPad apps and not from third-party applications without using AppleTalk or Bonjour?

    We have a Windows 2003/2008 server-based network with a dedicated print server which we would like to be able to print to over Wi-Fi.  How can I set up the printers on the iPad without downloading a third party application such as Print Central or Print N Share?  I want to just click the arrow and "Print" then choose the printer, which doesnt show up.  I want to be able to use the existing TCP/IP-based network that we have to reach these queues, not having to install Bonjour or AppleTalk to reach them.
    Thanks,
    KMQ7

    This would really be the "Holy Grail"   right now.  I think this a feature that every large organization requires. AirPrint works on a small scale, but is not really an enterprise class application.  In addition it uses the Bonjour discovery process which is difficult in a large LAN WAN environment.  For those that would remind me, I am aware of the enhancement link 

  • Windows 2008 Server RC 2(64bit) ,Crystal Reports11.5 Compatbility Resolve?

    Our company is moving to Windows 2008 Server RC2 64bit OS platform to run our reports. Will Crystal Reports 11.5 run on this OS platform? Right now it does not. Is there a resolution?

    Actually it is supported, but because CR is a 32 bit app everything on the server must also be running in 32 bit modes. Other issue is CR XI R2 is past it's patch life cycle so if there are any issues we can't fix them. CR 2008 SP 3 should work fine as well as CR XI R2 SP 6, which does have Windows 7 support which is the same as Windows 2008 Server.
    Check the link out for more info on what is and how to.
    What is the actual problem you are having?
    Thank you
    Don

  • Windows 2008 Server crashed - How to find location of remote shared files that they used to access on remote web app?

    We have a client that was running windows 2008 server.  A previous IT person had setup their system, so we were walking into a situation where there were many unknowns.  Server was mainly handling emails only, and we were able to get their exchange
    database off and export PSTs to hosted exchange via microsoft.
    Everything went fine with that, however one user said that he used to access files on the server via the remote web app as he described.  He would go to the following url:
    https://mail.theirdomain.com/remote/menu.aspx#
    and he would use his login and then he would see several links to folders.  He could then click on those and see his desired files.  
    We were able to get the server booted again, however we could not find any of the files he described on it at all, leaving me to suspect that perhaps this remote link was accessing another PC.  
    We have the old server up and running, however the link above is no longer active because we have pointed the domain to the new hosted exchange server.  As I am still learning and my boss wanted me to research this on my own and figure out how to find
    out where these files are located.  Any advice would be greatly appreciated.  
    Just as a note I did try access mail.localhost.com/remote/menu.aspx# on the server but this did not work.  Is there any way in the IIS 7 management console to figure out where this was pointing to?  

    I figured it out - The server was using sharepoint to host these files.  I browsed localhost:987 and opened the sharepoint site locally on the server.  They had several documents to be exported, however when clicking on Open in Explorer it was
    giving an error that local client was not configured.  I installed Desktop Experience and after that was able to open it in Windows Explorer and copy all files off.  

  • Windows 2008 Server R2 not loading Desktop

    Hi All,
    I have windows 2008 server R2 using as Database server.Today when i try to login it is showing two more user accounts in the login screen and i login to the server with administrator account but it was showing a blue screen(not blue screen error) with mouse
    pointer.I press Ctrl+Alt+Del and open task manager>new task>desktop and click open its showing that "windows cannot access the specified device,path or file.You may not have the appropriate permissions to acess the item.

    From cmd.exe session run SET then look for
    USERNAME=Administrator
    USERPROFILE=C:\Users\administrator
    If you see USERPROFILE=C:\Users\administrator.000 (or similar) then the original local administrator profile was corrupt or otherwise orphaned.
    In days past one could create a new account with local administrative rights, logon with new account, then after saving off docs, etc. from corrupt/abandoned profiles use
    Control Panel|Users and Passwords and delete the old profile stores. Then when you next logon a new profile is created from an image in
    \default user Have not tried this on anything newer vintage than server 2003 though.
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • Windows 2008 Server R2 & SAP Business One

    Does anyone have any experience, good or bad, with SAP Business One and Terminal Service on Windows 2008 Server R2?  We are finding a number of issues with this configuration and we are looking for any feedback that is out there.
    Here is the situation - our customer is running SAP Business One v2007 SP01 PL09 Hotfix4 on a Windows 2008 Server R2 machine.  All users (15 max) access SBO via Terminal Service to this machine, which also holds the databases (SQL Server 2005).  The machine currently has 20GB of RAM.
    What we are finding is:
    1) When any process related to SBO (SBO core or add-ons) consumes some portion of memory, none of that memory is ever released back to the O/S until SBO is completely closed.  So over the course of a day each user ends up simply consuming more and more memory as forms are opened for transactions.  While we do see this in Windows 2003 Server to some extent, at least some memory is released when a given form is closed.
    2) Once the system hits a point where around 75% of RAM is consumed the users start seeing application "hangs" and are forced to manually terminate SBO (via Task Manager) and restart.  There doesn't seem to be any paging or use of virtual memory (if my terms are right) in use.
    3) If the system is busy and a new window/form is opened the new window immediately (within one or two seconds) presents the "Not Responding" message on the new window.  Depending on the circumstances the application is simply waiting for resources and will continue opening normally.
    I would appreciate feedback from anyone who has experience with Windows 2008 Server R2; and especially using it for Terminal Services.  My personal feeling is that it is a platform that should be avoided but we would certainly like to hear what other folks have to say.
    Regards,
    Ross Unger
    Third Wave Business Systems

    I believe the supporting of this OS is still on Planned basis.  You may check with SAP support to give them a good user case to fight with any non-compatible issues.
    Thanks,
    Gordon

  • Windows 2008 Server Configuration - Help

    Hello All,
    I am not an expert in configuring servers and I have just started to learn. Please forgive me if I am doing something funny!
    I have a router with static IP address and DHCP enabled on the router. The router had the following configuration as shown below and the clients were obtaining IP address from the router and using the internet without a problem.
    Router Configutaion:
    Basic Setting:
    IP Address : 122.165.60.160 (My Wan Static IP)
    IP Subnet Mask : 255.255.252.0
    Gateway IP: 122.165.60.1
    DNS Address:
    Primary DNS : 203.145.184.32
    Secondary DNS: 203.145.184.13
    Lan TCP/IP Setup:
    IP Address: 192.168.2.1 (Router IP)
    IP Subnet Mask: 255.255.255.0
    DHCP Enabled:
    Statring IP : 192.168.2.11 
    Ending IP: 192.168.2.100
    Now, I have installed Windows 2008 R2 Server with Active Directory, DNS and DHCP, IIS. I have created a few users and did nothing more than that in the server.
    Server IP Settings
    Server IP: 192.168.2.5
    Subnet : 255.255.255.0
    Gateway : 192.168.2.1
    DNS: 127.0.0.1
    And when I tried to join the domain i created... corp.globe.com the clients were not able to find the domain I therefore changed the following settings in the router.
    DNS Address:
    Primary DNS : 203.145.184.32
    Secondary DNS: 192.168.2.5 (Server IP)
    After this change the clients were able to join the domain and login as well. However the clients were getting the IP from the router. I am facing a lot of problems as listed below.
    1. I am not able to ping the clients using the computer name from the server.
    2. Clients cannot ping other clients or server using name. (Suppose if I try... PING SYS1 .... It looks like it is trying to ping some 92.x.x.xx IP address) even if SYS1 IP address is 192.168.2.13
    3. Clients can access Internet, but I cannot browse anything in the server.
    Please help me in the configuration, or point me to some guide which describes the same. I tried to set up and enable the DHCP server using Windows 2008 machine and I disabled it DHCP on the router, clients where able to get the IP address from Windows 2008
    server, but they were not able to use internet. Please advise.
    Thanks for your time.

    Hi,
    And you cannot ping the clients using the computer name from the server?
    Did you turn off the firewall on server and client?
    If you are having problems connecting to Active Directory and you have already successfully verified network connectivity, there might be a name resolution problem. For more and detail information, please refer to:
    http://technet.microsoft.com/en-us/library/cc961921.aspx
    Regards.
    Vivian Wang

  • Install windows 2008 server r2 as a vm on windows 8.1 pro

    I am trying to install windows 2008 server r2 as a vm on an asus I7 4th gen. on windows 8 pro. It goes
    thru the install untill completing install and gives error the computer restarted unexpectedly or encountered an unxpexted error windows installation cannot proceed click ok to restart. I do the shift f10 and change the registery to force finsh the install.
    It boots up but when I try to do anything. It goes into  netio.sys BSOD issue

    I haven't run into that problem, but when setting up the OS, just
    remove the NIC from the settings, do the install, make sure it's running, then install the integration
    services, reboot, then add the NIC back in. 
    You could also use a legacy network adapter if that doesn't work.
     In any case I'm trying an install of Win2008R2 right now so I can see if I get the same problem...
    Bob Comer Microsoft MVP -- Hyper-V

  • Error 0x80070490 trying to launch VM without SCVMM on Windows 2008 Server R2

    Hello everybody,
    I get a weird issue trying to launch a VM.
    This is the current situation : I get a server, Windows 2008 R2. I've only install Hyper-V and Failover Cluster. I can create a VM but when I try to launch it, I get an error message into a popup (translated from french) : "The application encountered
    an error during modification of 'vm_name' state". "'vm_name' could not be initialize". "Could not initialize machine remoting system. Error 'Element not found'. (0x80070490). "Could not find a usable certificate. Error: 'Element not found'. (0x80070490)."
    So, I'm unable to launch my vm's.
    I'm not using SCVMM yet. I want to resolve this issue before.
    I read some articles and posts about SCVMM certificate issue but I'm not using SCVMM.
    More fun, I read articles about this issue but on Windows 2008 Server (not R2) : problem resolved by a fix, unapplicable on my Windows 2008 R2 :)
    I'm totalyblocked and ain't got no idea how I can resolve it.
    If someone gets I idea ...
    Cheers,
    Nicolas

    Environment: Windows 8.1 in an Active Directory Domain (2012R2) with MS Certficates Services support NAP/Health Registry, etc. 
    Error:  Attempts to start a Hyper-V VM on a machine generates the error message Error 0x80070490 trying to launch VM:
    "'vm_name' could not be initialize". "Could not initialize machine remoting system. Error 'Element not found'. (0x80070490). "Could not find a usable certificate. Error: 'Element not found'. (0x80070490)."
    Note: 
    VMM can manage other Hyper-V servers in environment from same machine, just not local machine.
    VMM on remote machine generates same error message when attempting to manage new VM machine
    Certificates - Service (Hyper-V Virtual Machine Management) on Local Computer shows 0 certificates under vmms\Personal
    Fixes Attempted and Failed except for #5!
    1) hotfix directly: Windows6.0-KB967902-x64.msu -> Failed: 0x80096002, Windows Update Standalone Installer.  The certificate for the signer of the message is invalid or not found.
    2) hotfix via pkgmgr: PkgMgr.exe has been deprecated. Please update scripts to use DISM.exe.  0x80070307
    3) Reset Certificates: 
     Start > Run > MMC
     Add the Certificates Snap-In
     Select Service Account
     Under the Select Account to Manager, select Hyper-V  Image Management Service
     Complete the Snap-In Wizard
     Expand the Certificates under Personal Category
     Notice the certificate generated has been created ‘for the future’ (assuming you’re suppose to revert the date & time to 2010, the certificate should display as invalid because it was created at 2013)
     Delete the Certificate(s)
     Go to the Services Console and Restart all Hyper-V Services
     Result: No certificate auto generated
    4) Uninstall / reinstall hyper-v service and management service addons from Windows features.  
    5) ‎did the following from http://technet.microsoft.com/en-us/library/ff935311(v=ws.10).aspx (WORKED!!! -> Note, their PS script has an error, add a dash(-) before the word recurse)
    reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization" /v "DisableSelfSignedCertificateGeneration" /f /t REG_QWORD /d 1
    24 ca 36 b5 bd 6d ef 7e eb aa a5 74 df e5 fd 41 ef ab 1c 29
    $certs = dir cert:\ -recurse | ? { $_.Thumbprint -eq "24ca36b5bd6def7eebaaa574dfe5fd41efab1c29" }
    $cert = @($certs)[0]
    $location = $cert.PrivateKey.CspKeyContainerInfo.UniqueKeyContainerName
    $folderlocation = gc env:ALLUSERSPROFILE
    $folderlocation = $folderlocation + "\Microsoft\Crypto\RSA\MachineKeys\"
    $filelocation = $folderlocation + $location
    icacls $filelocation /grant "*S-1-5-83-0:(R)"

Maybe you are looking for

  • Error in SAOP adapter : RFC to SOAP Synch Scenario

    Hi Experts, Scenario is "RFC to SOAP Synch". For creating this following this link : **************** - Scenario on RFC to SOAP Trying to send XML to SOAP receiver. Using Below details for SOAP: Website : http://www.webservicex.net/WS/WSDetails.aspx?

  • Adobe Reader XI protected mode problem

    I downloaded Reader XI and went to open a pdf that previously worked with Reader.  But Adobe Reader XI won't open (says problem with "protected mode").  I can't open any pdf's either on my computer or on the internet at trusted sights.  Troubleshooti

  • Show characteristic with zero figures in report

    Dear All, I have report as below: Material        Qty A                  0 B                  10 C                  5 D                  0 E                  2 I want to filter Material with zero quantity. I've already try with condition Qty = 0, but

  • Tweens don't work in multiple external AS2 SWFs loaded by AS3 SWF

    When I try to load a single external AS2 SWF in an AS3 parent SWF, scripted tweens using the mx.tween class work fine. However, when I load two or more external AS2 SWFs, the first will work, but in subsequent SWFs the tweens do not animate. Does any

  • After i load a java application, it shuts off

    I tried going on a chatroom where java is used. after it finishes loading the page all seems fine. after a couple of seconds java turns off and the chat screen goes black. Tried using it on IE and it works fine so i know its not the website.