Note
You must be connected as a member of the Domain Admins group to be able to grant or revoke privileges assigned
to an account. This capability is inherent to the Domain Admins group and is not configurable. There are no
default rights and privileges, except the ability for a member of the Domain Admins group to assign them.
This means that all administrative rights and privileges (other than the ability to assign them) must be
explicitly assigned, even for the Domain Admins group.
By default, no privileges are initially assigned to any account because certain actions will be performed as
root once smbd determines that a user has the necessary rights. For example, when joining a client to a
Windows domain,
add machine script
must be executed with superuser rights in most
cases. For this reason, you should be very careful about handing out privileges to accounts.
Access as the root user (UID=0) bypasses all privilege checks.
|