Devolved administration of DFS replicas

J

Jim Watts

We are starting to implement DFS within our Windows2000 Active Directory, to
replicate out application portfolios across campus. I want to delegate the
ability to configure and manage DFS to another person in our organisation.
The document
http://www.microsoft.com/windows2000/techinfo/administration/fileandprint/dfsbp.asp
explains how to delegate the ability to create and administer DFS, and after
i followed the recommendations everythin worked fine.

However, the DFS mmc snapin that's included in the Windows2003/XP adminpak
adds the ability to configure more DFS options, such as custom topologies
and replication intervals. My first question is, is this higher level of
configuration supported when running a Windows2000 AD, rather than a 2003
one. It all seems to work, but i need to be sure. I think that SP2 added
more DFS options to the directory (as detailed in Q321557) but didnt add the
features to the MMC.

My second question, concerns delegation again. The user to which I delegated
the ability to manage DFS can create roots and links etc, and configure
replicas. However they cannot change the topology options etc that are
exposed by the 2003/XP version of the DFS snapin. Whenever they try a simple
'access denied' message is displayed. Assuming that this functionaility is
supported within a Windows2000 AD, is it possible to delegate the ability to
mange the links etc?

Many thanks
Jim
--
Jim Watts, MCSA, MCSE
Technology Consultant
Directories, Authentication and Border Security
Information Systems Services
University of Southampton

Email: (e-mail address removed)
Phone: 023 8059 2280

***
 
T

Thomas Spencer[MS]

Jim,
In response to your questions:

Answer 1) The 2003 DFSGUI.msc is backwards compatible with Windows 2000 Domains.


Answer 2) To manage the FRS topology, the delegated administrator would need
access to objects in the following branch of AD:

CN=DFS Volumes,CN=File Replication Service,CN=System,DC=domain,DC=com,

where dc=domain,dc=com would be replaced with the customers actual Domain name.


Please let me know if this solves your problem or
if you would like further assistance.

I look forward to hearing from you.

Regards,

Thomas Spencer, MCP, MCSE, MCSA Windows 2000
Microsoft Partner Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top