You made a good point, I forgot about the delay.
 
I suppose I need to review my delegation model because if they can modify themselves to be included in any of the builtin groups, they have too many permissions already so using the restricted groups function would not be required.
 
Back to basics for me.
 
Thanks
 
James

Al Mulnick <[EMAIL PROTECTED]> wrote:
Hmm... I'm not sure this is the way to go for your requirements.  Restricted groups is going to have a delay before it puts the groups back to the way they *should* be. It sounds like you need a better system for delegation.  Can you expand on your requirements?

On 5/31/06, James Carter <[EMAIL PROTECTED]> wrote:
Sorry I should clarify, by User I mean an IT Helpdesk Account Creator
 
Single Domain  Windows 2003, FFL. I have delegated rights to various Security Groups for privileges in the domain.
 
James


James Carter <[EMAIL PROTECTED] > wrote:
Hi,
 
I am thinking of making all the builtin groups apart from the Administrators group part of the Restricted Groups function.
 
I don't want any user to add themselves to the Account, Backup,Server, Print Operators group for any length of time.
 
Or does anyone know of a simpler way to acheive this?
 
Regards,
 
James

Be a chatter box. Enjoy free PC-to-PC calls with Yahoo! Messenger with Voice.


New Yahoo! Messenger with Voice. Call regular phones from your PC and save big.



Do you Yahoo!?
Everyone is raving about the all-new Yahoo! Mail Beta.

Reply via email to