On Wednesday, July 17, 2013 10:11 AM CDT, Gaiseric Vandal <[email protected]> wrote: > According to the net man page > > > In order for Samba to be joined or unjoined remotely an account > must be > used that is either member of the Domain Admins group, a member > of the > local Administrators group or a user that is granted the > SeMachineAccountPrivilege privilege. > > > > > The simplest thing is probably to have the Domain IT group be a member > of the local admin group on each machine. I don't know if you would > need to grant them the SeMachineAccountPrivilege. > > > > On 07/17/13 09:44, Donny Brooks wrote: > > > > > > > > On Saturday, July 13, 2013 04:43 AM CDT, Marc Muehlfeld > > <[email protected]> wrote: > > > >> Hello Donny, > >> > >> Am 12.07.2013 21:34, schrieb Donny Brooks: > >>> On the old domain, which was setup before I got here, > >> > our IT section was in an ldap group that allowed us to > >> > join PC's to the domain ... > >> > >> http://wiki.samba.org/index.php/Samba_AD_DC_HOWTO/AD_Delegation#Delegating_.27Joining_Computers_to_the_domain.27-permissions > >> > >> > >> > >> > >> > ... and when the prompt came up in windows to > >> > install software we could log in as ourselves. > >> > >> What do you mean by this? Do you want to have a group of users > >> automatically in the "administrator" group on your workstations? > >> > >> http://community.spiceworks.com/how_to/show/2123-add-an-active-directory-group-to-the-local-administrator-group-of-workstation-s > >> > >> If you mean something else, please give some more details. > >> > >> > >> > >> Regards, > >> Marc > >> > >> > >> > >> > >> > > > > Yes, on the old domain we had all of our IT staff in a group that was able > > to join pcs to the domain and install software by inputting their domain > > credentials when prompted. Looking at the first link that is for Samba 4.X. > > We are on Samba 3.5.10 so that does not apply. > > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba Looks like I need to do this here: http://www.samba.org/samba/docs/man/Samba-HOWTO-Collection/groupmapping.html
And map our itgroup to the Domain Admins group. Although we do have a Domain Admins group in ldap. Should that cause an issue? -- Donny B. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba
