Basic Monitoring Permissions


hi guys,

maybe silly question, have been looking around solution , cannot find clean way to achieve what want achieve.

i have team have no administrative permissions on domain, need them have basic access bunch of servers (including domain controller) monitoring hardware/eventlogs/disk management , scheduled tasks.

i wish via gpo.

what best way in opinion? lowest permission can give user can still access a domain controller?

josh.

to delegate read permission non-administrators: http://blogs.technet.com/b/janelewis/archive/2010/04/30/giving-non-administrators-permission-to-read-event-logs-windows-2003-and-windows-2008.aspx

for hardware diagnosis, can use event logs or ask manufacturer more information.

for scheduled tasks, depends of scheduled. can configure scheduled scripts add output in text files , grant these users permissions these files.

to specify members of local groups, consider using restricted groups group policy: http://www.windowsecurity.com/articles/using-restricted-groups.html

to change file / folders permissions, refer that: http://technet.microsoft.com/en-us/library/cc756952%28v=ws.10%29.aspx

more if ask them here: http://social.technet.microsoft.com/forums/en-us/winservergp/threads



this posting provided "as is" no warranties or guarantees , , confers no rights.   

microsoft student partner 2010 / 2011
microsoft certified professional
microsoft certified systems administrator: security
microsoft certified systems engineer: security
microsoft certified technology specialist: windows server 2008 active directory, configuration
microsoft certified technology specialist: windows server 2008 network infrastructure, configuration
microsoft certified technology specialist: windows server 2008 applications infrastructure, configuration
microsoft certified technology specialist: windows 7, configuring
microsoft certified technology specialist: designing , providing volume licensing solutions large organizations
microsoft certified professional: enterprise administrator
microsoft certified professional: server administrator
microsoft certified trainer



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client