Networking Forums

Networking Forums > Computer Networking > Windows Networking > IAS Radius Delegation

Reply
Thread Tools Display Modes

IAS Radius Delegation

 
 
Jim Watts
Guest
Posts: n/a

 
      01-13-2005, 09:39 AM
Hi,

I've been asked to provide Radius via IAS on our Windows 2003 Domain
Controllers. I would like to delegate control of the IAS/Radius
configuration to other members of my team, without giving them Administrator
permissions on the Domain Controllers. Can anybody tell me if this is
possible, as i've not yet been able to work out where the IAS config data is
stored, or whether access to it can be delegated.

Many thanks
--
Jim Watts,
Technology Consultant
Information Systems Services
University of Southampton


--
--
Jim Watts,
Technology Consultant
Information Systems Services
University of Southampton


 
Reply With Quote
 
 
 
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      01-13-2005, 06:04 PM
There is no separate "IAS Administrator" role. Since IAS is a security feature,
and since you must be a domain administrator to register IAS in Active Directory,
only domain administrators can manage IAS.

Steve Riley
(E-Mail Removed)



> Hi,
>
> I've been asked to provide Radius via IAS on our Windows 2003 Domain
> Controllers. I would like to delegate control of the IAS/Radius
> configuration to other members of my team, without giving them
> Administrator permissions on the Domain Controllers. Can anybody tell
> me if this is possible, as i've not yet been able to work out where
> the IAS config data is stored, or whether access to it can be
> delegated.
>
> Many thanks
>



 
Reply With Quote
 
Wayne Tilton
Guest
Posts: n/a

 
      01-13-2005, 06:53 PM
Steve Riley [MSFT] <(E-Mail Removed)> wrote in
news:(E-Mail Removed):

While what Steve says is correct, it is fairly easy to do what you want
by changing the permissions on the %SystemRoot%\system32\IAS directory
and the files contained in it (.MDB and .LDB's). You can also use a tool
like SetACL to grant your IAS admins the rights to control the IAS
service and TS config and GPO to allow them to log on to the DC's.
Registering IAS in AD just makes the IAS server a member of the "RAS and
IAS Servers" group so it can read the user attributes, so, security not
withstanding, you can delegate that right, too.

HTH,

Wayne Tilton

> There is no separate "IAS Administrator" role. Since IAS is a security
> feature, and since you must be a domain administrator to register IAS
> in Active Directory, only domain administrators can manage IAS.
>
> Steve Riley
> (E-Mail Removed)
>
>
>
>> Hi,
>>
>> I've been asked to provide Radius via IAS on our Windows 2003 Domain
>> Controllers. I would like to delegate control of the IAS/Radius
>> configuration to other members of my team, without giving them
>> Administrator permissions on the Domain Controllers. Can anybody tell
>> me if this is possible, as i've not yet been able to work out where
>> the IAS config data is stored, or whether access to it can be
>> delegated.
>>
>> Many thanks
>>

 
Reply With Quote
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      01-13-2005, 10:31 PM
That is an unsupported configuration and is not something we test.

Steve Riley
(E-Mail Removed)



> Steve Riley [MSFT] <(E-Mail Removed)> wrote in
> news:(E-Mail Removed):
>
> While what Steve says is correct, it is fairly easy to do what you
> want by changing the permissions on the %SystemRoot%\system32\IAS
> directory and the files contained in it (.MDB and .LDB's). You can
> also use a tool like SetACL to grant your IAS admins the rights to
> control the IAS service and TS config and GPO to allow them to log on
> to the DC's. Registering IAS in AD just makes the IAS server a member
> of the "RAS and IAS Servers" group so it can read the user attributes,
> so, security not withstanding, you can delegate that right, too.
>
> HTH,
>
> Wayne Tilton
>
>> There is no separate "IAS Administrator" role. Since IAS is a
>> security feature, and since you must be a domain administrator to
>> register IAS in Active Directory, only domain administrators can
>> manage IAS.
>>
>> Steve Riley
>> (E-Mail Removed)
>>> Hi,
>>>
>>> I've been asked to provide Radius via IAS on our Windows 2003 Domain
>>> Controllers. I would like to delegate control of the IAS/Radius
>>> configuration to other members of my team, without giving them
>>> Administrator permissions on the Domain Controllers. Can anybody
>>> tell me if this is possible, as i've not yet been able to work out
>>> where the IAS config data is stored, or whether access to it can be
>>> delegated.
>>>
>>> Many thanks
>>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Delegation of IP address change Abhi Windows Networking 1 07-02-2008 07:04 AM
DNS Reverse Zone Delegation Christian Barmala Linux Networking 1 12-08-2006 07:15 AM
Active Directory DNS Replication and Delegation JDP-PE Windows Networking 2 10-01-2005 12:23 AM
DNS and Subdomain Delegation Charles Tryon Linux Networking 0 06-05-2005 02:38 AM
User Rights Delegation Rudi ludick Windows Networking 0 03-02-2004 09:48 AM



1 2 3 4 5 6 7 8 9 10 11