Displaying 20 results from an estimated 10000 matches similar to: "GPO administration right on the station for ordinary user"
2017 Apr 03
0
GPO administration right on the station for ordinary user
Hai Marc,
But thats missing info.. :-(
Maybe its also a good thing to add just after the first picture on the wiki.
That the security filter on the GPO MUST have "authenticated users" or Domain computer group.
You decide.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens Marc Muehlfeld
> via samba
>
2017 Apr 03
0
GPO administration right on the station for ordinary user
1ste google search.
https://social.technet.microsoft.com/wiki/contents/articles/7833.how-to-make-a-domain-user-the-local-administrator-for-all-pcs.aspx
try it and report back.
This should work, i use the same for my remote desktop users.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens Gabriel O. Franca
> via samba
2017 Apr 03
3
GPO administration right on the station for ordinary user
Hi Louis,
Am 03.04.2017 um 17:01 schrieb L.P.H. van Belle via samba:
> But thats missing info.. :-(
>
> Maybe its also a good thing to add just after the first picture on the wiki.
> That the security filter on the GPO MUST have "authenticated users" or Domain computer group.
> You decide.
thanks for bringing this up. I will verify this later.
I'm 85% sure, I never
2017 Apr 03
2
GPO administration right on the station for ordinary user
The Wiki page you pointed to describes a modification to the *Default
Domain Policy*. This is probably why you never met the issue I
described. As I reported on my previous post, the Default Domain Policy
was the only one that kept working after the Microsoft update. All the
other GPOs that I had set stopped being applied.
2017 Apr 04
1
GPO administration right on the station for ordinary user
Hai Marc,
Well first, no you did nothing wrong here.
This was fine when you wrote it, but after the BadLock Bug,
Microsoft change the way some policies are applied.
A good explaination here.
http://www.mistercloudtech.com/2016/06/22/june-14th-windows-update-changes-group-policy-security-filtering/
Best regards,
Louis
> -----Oorspronkelijk bericht-----
> Van: Marc Muehlfeld
2017 Apr 03
0
GPO administration right on the station for ordinary user
Am 03.04.2017 um 17:21 schrieb Marc Muehlfeld via samba:
> Am 03.04.2017 um 17:01 schrieb L.P.H. van Belle via samba:
>> But thats missing info.. :-(
>>
>> Maybe its also a good thing to add just after the first picture on the
>> wiki.
>> That the security filter on the GPO MUST have "authenticated users" or
>> Domain computer group.
>> You
2017 Apr 03
1
GPO administration right on the station for ordinary user
> I verified the Wiki doc and here it works like described (without
> setting a filter). I did exactly what is described in the Wiki. To
> verify, I added a regular domain user to the domain group I set in the
> GPO, and after I log in as this user on a domain member, this account
> had local admin permissions.
>
> Doesn't this work in your installation? What happens
2015 May 22
5
Samba4 Disable USB ports
2015-05-22 13:32 GMT+02:00 Gabriel Franca <gabriel.franca at gmail.com>:
>
> I found it strange more and something I have already noticed a while.
>
> No GPO is applied when the User is the "Domain Users", so I wonder if I'm
> doing something wrong or I have to change something.
>
> I believe the "Domain Users" are not allowed to change the
2015 May 22
5
Samba4 Disable USB ports
Hello Gabriel,
I recommend you use
gpupdate /force
on the windows command line after login.
The results of above command can be checked afterwards with the
"gpresults" command.
Can be you have an permission problem on your samba server. Only skimmed
ofver the thread but did you try
samba-tools ntacl sysvolreset
on your samba server?
achim~
Am 22.05.2015 um 12:08 schrieb Gabriel
2015 May 22
2
Samba4 Disable USB ports
Good morning everyone,
Gabriel: I haven't had a chance to test this yet, but I'm also needing the
same IE: Domain Users to have the GPO applied. Did you come right with this?
Andrey: Thank you for letting me know about the SysVol replication across
DC's, I haven't enabled this yet and will be doing so, is there anything I
should watch out for? I'll just be using the "
2015 May 22
1
Samba4 Disable USB ports
Hello Gabriel,
Am 22.05.2015 um 15:23 schrieb Gabriel Franca:
> Good morning people,
>
> I make the case that Achim Gottinger passed.
>
> samba-tool ntacl sysvolreset and received the following information:
> Segmentation fault (core of the recorded image)
>
> then sent a samba-tool ntacl sysvolcheck and received the following:
> ERROR (<type
2015 May 25
2
Samba4 Disable USB ports
Good morning List
On Friday I had to leave so I could no longer continue with our lab.
Weekend and holy all have to rest as much as possible. = D
So I'm back and I will put the smb.conf for analysis.
# Global parameters
[global]
workgroup = CMC
realm = CMC.CORP
netbios name = SAMBA
server role = active directory domain controller
dns forwarder =
2015 May 20
2
Samba4 Disable USB ports
Hi Louis,
Thank you very much for your speedy response. I'll definitely go ahead and
investigate further.
Much appreciated.
Regards.
Neil Wilson.
On Wed, May 20, 2015 at 1:24 PM, L.P.H. van Belle <belle at bazuin.nl> wrote:
> yes, this is possible, by GPO.
>
> In GPO, go to:
> (user or computer )Configuration
> - Policy
> ? Administrative
2015 May 27
1
Samba4 Disable USB ports
Good Morning Achim,
Follows the exit of the requested command.
Now the GPO funny not work when user is only the ?Domain Users?
getfacl /var/lib/samba/sysvol/
getfacl: Removing leading '/' from absolute path names
# file: var/lib/samba/sysvol/
# owner: root
# group: 3000000
user::rwx
user:root:rwx
user:3000000:rwx
user:3000003:r-x
group::rwx
group:3000000:rwx
group:3000001:rwx
2016 Jul 13
2
Attempting to access LDAP backend gives "Strong(er) Authentication Required"
LDAP can be use in clear text mode or with start_tls. There is still LDAPS
which can also be used. Any of these should be used to authenticate users
as LDAP[s] is not meant to authenticate anything, it's a DB.
Kerberos should be used for authentication as it is meant for that purpose
and could grant your users possibility to have SSO. More secure for admins,
more simple for users...
I have
2015 Feb 12
2
Migrate Server Samba 4 to another server
Good morning guys,
need to migrate a samba 4.1.16 of Sernet that is installed on a CentOS 6 for a centOS7. (Old server giving hardware problem)
Rowland gave me a while ago a script to back up the samba structure 4 and to restore what should I do? is that performing this procedure can migrate? or do I have to put all computers in the field again reconfigure profile etc ???
Kind Regards,
2015 Aug 13
2
Problem with Samba 4.0.4 to 4.1.19 update
Good morning Rowland.
Today there are 2 servers with Samba 4.1.19
1) Samba 4.1.19 compiled used for the control domain (AD)
2) using Samba 4.1.19 Sernet package I used the command "samba-tool domain join" to use the Squid authenticating via NTLM.
Before I was as follows:
1) Samba 4.0.4 compiled AD
2) using Samba 4.1.19 Sernet package I used the command "samba-tool domain
2015 Aug 13
4
Problem with Samba 4.0.4 to 4.1.19 update
Good morning friends,
I have the following structure:
Centos 6.6
1) AD samba using .tgz package
2) using the proxy Sernet packages which use command: samba-tool domain join XXX.corp DC -U Administrator --realm = XXX.corp and set the squid via NTLM.
Issues:
1) after the update I get the following messages in / var / log / messages:
Aug 13 04:08:56 kernel samba: Out of memory: Kill process
2016 Jun 15
2
weird error rights in folders
Hi all,
here the company was using the packages Sernet-samba version 4.2.xx
I removed it and started compiling it to version 4.4.4
I took only the smb.conf.
The problem is that when I click the right button and go on the Security
tab get this message.
"As the permissions on home (\\ samba) are not sorted correctly, some of
them may have no effect."
Is there any command for me to
2015 Aug 13
2
Problem with Samba 4.0.4 to 4.1.19 update
Hello Rowland
Talking to users at that time discovered the following:
They remove the machine network cable, put the User and Password them the domain, after the windows open the desktop they connect the network cable back in the machine and get to work.
If you do this procedure is giving User and wrong password!
On the issue of time the 2 DC's station using ntp.
I stopped the samba