Article ID: 911604 - Last Review: November 1, 2006 - Revision: 1.4 Delegating DFS replication in Windows Server 2003 R2
On This PageINTRODUCTIONDistributed File System (DFS) replication uses the Active
Directory directory service to store configuration objects. When you use Active
Directory, you can delegate user rights more exactly. The DFS Management
feature provides high-level delegation support. This support lets you grant
users the ability to create a replication group. This support also lets you
grant users administrative rights on a replication group that has already been
created. This article describes how to directly modify the permissions on the
configuration objects for each replication group. MORE INFORMATIONConfiguration objectsIt is useful to have an overview of all objects before you view each object in detail. This section describes the objects that are used to configure DFS replication. The permissions to these objects determine which users can perform specific operations on replication groups.Global objectsGlobal objects configure the replica set as a whole. For example, global objects configure the number of replicated folders. Global objects also configure the connections between each member of the replication group.msDFSR-GlobalSettingsThis object is created at the following times:
The only security modification to this object that we recommend is to grant users the right to create msDFSR-ReplicationGroup child objects in this container. To use DFS Management for this task, perform the Delegate Management Permissions action on the Replication node. msDFSR-ReplicationGroupThis object contains all the global settings that are specific to a single replication group. To modify the permissions on this container in DFS Management, perform the Delegate Management Permissions action on a replication group. You can grant a user administration rights on a replication group. You can also grant the user control of the msDFSR-ReplicationGroup object and of all the child objects for a replication group. The following attributes are stored in this object:
msDFSR-ContentThis object is created under the msDFSR-ReplicationGroup object when the replication group is created. The msDFSR-Content object contains an msDFSR-ContentSet object for each replicated folder in the replication group.Note No important attributes are stored in this object. msDFSR-ContentSetAn msDFSR-ContentSet object is created for each replicated folder in the replication group. The following attributes are stored in this object:
msDFSR-TopologyThis object is created under the msDFSR-ReplicationGroup object when the replication group is created. The msDFSR-Topology object contains an msDFSR-Member object for each member of the replication group.Note No important attributes are stored in this object. msDFSR-MemberAn msDFSR-Member object is created for each member of the replication group. This object references the computer object for the member. This object contains an msDFSR-Connection object for each connection where this member is the receiving member of the connection. The following attributes are stored in this object:
msDFSR-ConnectionAn msDFSR-Connection is created as a child of an msDFSR-Member object for each incoming replication connection to that member. The following attributes are stored in this object:
Server-local objectsServer-local objects exist in the computer account for each server that participates in a replication. These objects configure individual members of the replication group.msDFSR-LocalSettingsThis object is the top level container for DFS replication objects on a computer account.msDFSR-SubscriberAn msDFSR-Subscriber object is created for each replication group to which a server belongs. This object contains an msDFSR-Subscription object for each replicated folder in the replication group that is specified by the msDFSR-Subscriber object. The following attributes are stored in this object:
msDFSR-SubscriptionThe msDFSR-Subscription object contains settings that are unique to each replicated folder on the server. The following attributes are stored in this object:
Detailed delegationGrant permissions to create a replication groupThis action is one of the two delegation actions that are available in DFS Management. To manually perform this action in Active Directory Users and Computers, follow these steps:
Delegate administrative rights to a replication groupThis is the other delegation action that is available in DFS Management. To manually perform this action in Active Directory Users and Computers, follow these steps:
Manage local system settings without being a local administratorTypically, the user must be an administrator to manage local computer settings. To enable a user who is not an administrator to manage local computer settings, grant the user direct control of the required objects in Active Directory. To do this, follow these steps:
Control of all replication groupsTo grant a user control of all existing and future replication groups in a domain, follow these steps:
Add/Remove/Modify replicated foldersTo grant a user rights only to modify, to add, or to delete a replicated folder, follow these steps:
Add/Remove/Modify members and connectionsTo grant a user rights only to modify, to add, or to delete members and connections, follow these steps:
Generate a report on a replication groupTo generate a diagnostic report, a user must be a local administrator of the servers that are part of the report.APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
