Solved

Enable a user to only change certain items in AD

Posted on 2001-06-13
4
120 Views
Last Modified: 2010-04-13
We are running Win 2k server w/ Exchange 2k.  I need to enable the HR Mgr to edit personal info in the properties of each user so that it shows up in the Global Address List.  Is there a way to allow the HR Mgr to edit info in certain tabs of the users properties?  I would prefer not to give this person Account Operator permissions.  An example is this:

I create a new user named Jane Doe.  The HR Mgr now needs to enter Jane's info for address, telephones, organization in the corresponding tabs in AD Users.  The HR Mgr should not be able to edit any other tabs.

Thanks.
0
Comment
Question by:robinsonbpc
  • 2
4 Comments
 
LVL 32

Accepted Solution

by:
jhance earned 200 total points
ID: 6186211
That's a tricky problem.  I don't think you can selectively limit certain fields in the User Manager.  It an all or nothing proposition.  (Of course if there _is_ a way, I'm sure someone will point it out....)

I've seen this approached, however, using the following technique.  You need to use a SERVICE (and you probably need to either write one or get someone to write one) so that you have an application that runs with sufficient privilege on the machine to make the changes to the user account database.  The service either talks to the account management functions directly or uses one of the command line utils that modify user accounts to update the accounts.  Then you provide a user interface program that your HR guy can run that talks to the service.  The service only accepts certain requests from the user interface and so it only permits allowed operations.

It's a bit of work but I think this is the best way to accomplish this.
0
 
LVL 5

Expert Comment

by:cempasha
ID: 7858897
Dear questionner/expert(s)

No comment has been added lately, so it's time to clean up this TA.
I'll leave a recommendation in the Cleanup topic area that this question is to be:

- PAQ'd and pts removed

Please leave any comments here within the next seven days.

==> PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER ! <==

PaSHa

Cleanup volunteer
0
 
LVL 32

Expert Comment

by:jhance
ID: 7863475
I disagree.  My comment is a valid solution here and should be FORCE ACCEPTED.
0
 

Expert Comment

by:SpideyMod
ID: 7924289
Answered by jhance

SpideyMod
Community Support Moderator @Experts Exchange
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now