Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to delegate the right to "replicate now"?

Status
Not open for further replies.

porcellir

MIS
Nov 20, 2002
8
0
0
US
This is my problem. I have just migrated a multimaster NT 4.0 environment into a single domain environment with WIN2K. I only want myself and a couple of other users to be Enterprise/Domain Admins.

I created groups and OUs for other locations for their admins.
OU - New York
Group - New York Admins

I then delegated full control of the OU to the group mentioned. I also added the remote locations' admins to the DHCP, DNS, & WINS Admins Groups. They were also added to the Newly created group, Server Operators and Account Managers groups.

I also created a GPO for each OU to add the newly created group to the Local Administrators Group on each individual PC in their respective OU. This was done with the Restricted Group GPO setting. Now they can do everything they need to do, except force replication to occur between domain controllers using the AD Sites and Services Snap-In.

My question is simple. How do I accomplish granting them this ability? I have searched high and low on TechNet and Google, and alas, I have come away empty handed. Please help. It would be greatly appreciated.

Thanks,

--Roger
 
did you tried to use delegation wizard on Sites ?

Victor K
psas@canada.com
MCSE+I;MCSA;MCSE(w2k);CNE(5.1);MCNE(6);CIWSP;CIWSA.
 
Yeah. It was one of the first things I tried. I can't believe that this is as hard as it seems...

--Roger
 
check an ACL's on each NTDS part of the sites. Do you see those persons who must be able to replicate?
Add them to the Ent.Admin.Group.

OK?

Victor K
psas@canada.com
MCSE+I;MCSA;MCSE(w2k);CNE(5.1);MCNE(6);CIWSP;CIWSA.
 
Yes they show up, and no I will not add them to the Enterprise Admins Group. My whole point to this is to not give these users enterprise wide admin privelledges.
 
I had the same problem in my test environment. I just user EntAdmin group because it was not importans in test env.
But definitely there is a permissions problem. Check it very carefully.

It is so hard to give such an adviced when not looking at the problemed system... :(


good luck

Victor K
psas@canada.com
MCSE+I;MCSA;MCSE(w2k);CNE(5.1);MCNE(6);CIWSP;CIWSA.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top