I want to create an active directory group. The group has certain permissions for a certain active directory folder. The folder contains user objects.
The group can create users, modify users, reset passwords, unlock users, enable and disable them. All these operations will only be allowed in that folder.
I don't want to use a pre-defined group.
Members of the group will not log onto the server directly. They will enter their credentials into an application and it will perform the operations on their behalf.
I've tried doing it myself but it did not work so I'd like total guidance in this.