Solved

Enable a user to only change certain items in AD

Posted on 2001-06-13
4
122 Views
Last Modified: 2010-04-13
We are running Win 2k server w/ Exchange 2k.  I need to enable the HR Mgr to edit personal info in the properties of each user so that it shows up in the Global Address List.  Is there a way to allow the HR Mgr to edit info in certain tabs of the users properties?  I would prefer not to give this person Account Operator permissions.  An example is this:

I create a new user named Jane Doe.  The HR Mgr now needs to enter Jane's info for address, telephones, organization in the corresponding tabs in AD Users.  The HR Mgr should not be able to edit any other tabs.

Thanks.
0
Comment
Question by:robinsonbpc
  • 2
4 Comments
 
LVL 32

Accepted Solution

by:
jhance earned 200 total points
ID: 6186211
That's a tricky problem.  I don't think you can selectively limit certain fields in the User Manager.  It an all or nothing proposition.  (Of course if there _is_ a way, I'm sure someone will point it out....)

I've seen this approached, however, using the following technique.  You need to use a SERVICE (and you probably need to either write one or get someone to write one) so that you have an application that runs with sufficient privilege on the machine to make the changes to the user account database.  The service either talks to the account management functions directly or uses one of the command line utils that modify user accounts to update the accounts.  Then you provide a user interface program that your HR guy can run that talks to the service.  The service only accepts certain requests from the user interface and so it only permits allowed operations.

It's a bit of work but I think this is the best way to accomplish this.
0
 
LVL 5

Expert Comment

by:cempasha
ID: 7858897
Dear questionner/expert(s)

No comment has been added lately, so it's time to clean up this TA.
I'll leave a recommendation in the Cleanup topic area that this question is to be:

- PAQ'd and pts removed

Please leave any comments here within the next seven days.

==> PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER ! <==

PaSHa

Cleanup volunteer
0
 
LVL 32

Expert Comment

by:jhance
ID: 7863475
I disagree.  My comment is a valid solution here and should be FORCE ACCEPTED.
0
 

Expert Comment

by:SpideyMod
ID: 7924289
Answered by jhance

SpideyMod
Community Support Moderator @Experts Exchange
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Employees depend heavily on their PCs, and new threats like ransomware make it even more critical to protect their important data.
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question