Home > Ask the Enterprise Desktop Experts > Questions & Answers > Windows server access management in Active Directory
Ask The Enterprise Desktop Expert: Questions & Answers
EMAIL THIS

Windows server access management in Active Directory

Bradley Dinerman EXPERT RESPONSE FROM: Bradley Dinerman

Pose a Question
Other Enterprise Desktop Categories
Meet all Enterprise Desktop Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 November 2007
I need to move our accounting server down to our server room and put it on the domain. It is currently on a "mini network" in the accounting office. Once I have it on the domain, I need to make it so that only the accounting group, domain admin and backup operator have access to this server. How can I accomplish this? We are on a Windows Server 2003 domain with Active Directory.

>
EXPERT RESPONSE

There are different levels of Active Directory server access that you can set: access to those coming in through network shares, access to those logging on at the console or access to those logging on through a remote desktop session.

You can set access for those coming in through the Windows network by sharing the particular folders of interest. When logged on to the server, right click any folder and select Sharing. Give the share a convenient name, such as "Financial," and set the permissions. You'll most likely want to provide Full Control to Domain Admins and the accounting groups. The Backup Operators group probably won't need control at the share level.

You can also control who has the ability to log on to the console. When you join the server to the domain, the Administrators, Domain Administrators and Backup Operators groups are automatically assigned the permission to log on locally. If you also want members of the Accounting group to have this right, go into the Local Security Policy console from Administrative Tools in the Start menu. Then drill-down into the Local Policies > User Rights Assignment node and find the entry for Allow Log On Locally. You can add the domain Accounting group from there.

And finally, if you want the Accounting group to be able to log on through a Remote Desktop session, then go into the Computer Management console, drill down into System > Local Users and Groups > Groups. Then, add Accounting to the Remote Desktop Users group.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Desktop Solutions - Windows for Enterprise
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts