怎么授权计算机用户,如何授权移动计算机账户

查看此文章使用产品

文章ID:818091

最近检查:2006年10月30日

修订版本:1.1

概要:

步骤1:识别用户或组和目标OU

要给指定的用户或组授予移动计算机账号的权限,你首先必须:

·识别授予移动计算机账号的用户和组

·识别指定用户和组将要执行计算机账号移动权限的指定OU

步骤2:授予用户或组从计算机容器移除计算机的权限

1、 点击开始,指向程序,指向管理工具,点击Active Directory Users and Computers

2、 在Active Directory 用户和计算机内,点击视图,然后点击高级功能

3、 右击计算机,然后点击属性

4、 点击安全标签,选择高级

5、 在计算机的访问控制设置 对话框中,点击“添加”,点击你将要授予他从计算机容器中删除计算机权限的用户或组的名字,然后点击“确定”。

6、 点击“高级”,在“计算机高级安全设置”对话框中,选择刚才添加的用户或组,点击编辑。(此处为译者加)在计算机的权限项目对话框中,点击“应用到”,选择只是这个对象。

7、 在权限列表中,找到“删除计算机对象”选项,并勾选旁边的复选框。点击确定。

8、 在计算机访问控制设置对话框中,点击添加,点击你将要授予他从计算机容器移除计算机的用户或组,然后点击OK。

9、 点击“高级”,在“计算机高级安全设置”对话框中,选择刚才添加的用户或组,点击编辑。(此处为译者加)在计算机的权限项目对话框中,点击“应用到”,选择只是这个对象。

10、 在“权限”列表中,找到“写入全部属性”选项并选择旁边的“允许”选项,然后点击确定。

步骤3:授予用户或组移动计算机到指定OU的权限

1. 在Active Directory 用户和计算机里,右击允许用户和组可以移动计算机账户的指定OU,并选择属性。

2. 点击“安全”标签,然后点击高级。

3. 在计算机的访问控制设置对话框,点击添加,点击将要被授予可从此容器移动计算机权限的用户或组的名字。然后点击确定。

4. 点击“高级”,在“计算机高级安全设置”对话框中,选择刚才添加的用户或组,点击编辑。(此处为译者加)在权限列表中,选择“创建计算机对象”权限并选择旁边的允许选项,然后点击“确定”三次。

原文:

How to Grant Permission to Move Computer Accounts

Article ID

:

818091

Last Review

:

October 30, 2006

Revision

:

1.1

On This Page

SUMMARY

This article describes how to grant permission to move computer accounts to a designated user or group. Occasionally you may want to move computer accounts to reflect changes in organizational or managerial structure, to account for a transfer of equipment ownership, or to make it easier to apply Group Policy.

For example, many organizations put all new computer accounts in the Computers container in Active Directory. However, this makes it difficult to keep track of which computers belong to which departments. Additionally, Group Policy cannot be applied to the Computers container because it is not an organizational unit. When you keep all computer accounts in the same container, this also limits your ability to delegate administrative control of those accounts. By moving accounts to the appropriate Active Directory organizational unit, this more accurately reflects the actual distribution of resources in the organization, and it enhances your ability to delegate administrative duties.

To grant permission to move computer accounts to a designated user or group, first identify the user or group that will be granted this permission, and then identify the destination organizational unit where computer accounts will be moved. Next, grant the user or group permission to remove computers from the present location (for example, the Computers container), and then grant the user or group permission to move computers to the destination organizational unit. To do this, follow these steps.

Step 1: Identify the User or Group and the Destination Organizational Unit

To grant permission to move computer accounts to a designated user or group, you must first:

?

Identify the user or group that will be granted permission to move computer accounts.

-and-

?

Identify the destination organizational unit where the user or group will be permitted to move computer accounts.

Step 2: Grant the User or Group Permission to Remove Computers from the Computers Container

1.

Click Start, point to Programs, point to Administrative Tools, and then click Active Directory Users and Computers.

2.

In Active Directory Users and Computers, click View, and then click to select Advanced Features.

3.

Right-click Computers, and then click Properties.

4.

Click the Security tab, and then click Advanced.

5.

In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.

6.

In the Permission Entry for Computers dialog box, click This object only in the Apply onto list.

7.

In the Permissions list, find the Delete Computer Objects permission, click to select the Allow check box next to this permission, and then click OK.

8.

In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to remove computers from the Computers container, and then click OK.

9.

Click the Properties tab, and then click computer objects in the Apply onto list.

10.

In the Permissions list, find the Write All Properties permission, click to select the Allow check box next to this permission, and then click OKthree times.

Step 3: Grant the User or Group Permission to Move Computers to the Destination Organizational Unit

1.

In Active Directory Users and Computers, right-click the destination organizational unit where the users or group will be permitted to move computer accounts, and then click Properties.

2.

Click the Security tab, and then click Advanced.

3.

In the Access Control Settings for Computers dialog box, click Add, click the name of the user or group to whom you want to grant permission to move computers into this container, and then click OK.

4.

In the Permissions list, find the Create Computer Objects permission, click to select the Allow check box next to this permission, and then click OK three times.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值