?
Solved

adding users and managing mailboxes without domain admin rights

Posted on 2004-09-01
7
Medium Priority
?
243 Views
Last Modified: 2013-12-03
I have a need for our help desk to add/delete user accounts plus manage distribution lists in a windows 2000 environment. I don't want them to have full rights. What is the easiest way?
0
Comment
Question by:gaskew
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 11953822
this is kind of a catch 22 problem,,,, think about it,,, if you give them rights to add/delete accounts,, this means that they can also change anyone's password, INCLUDING any administrator account... so if you enable a user to add/delete accounts,, you are essentially giving them the administrator password as well,,, since they can change it at any time.   Of course you will know it has been changed,,, since you couldn't log on with the old password anymore.  
0
 
LVL 22

Accepted Solution

by:
kristinaw earned 1000 total points
ID: 11953973
gaskew,

actually, you can delegate the rights to manage ONLY the users you wish your help desk to have rights to. This is not a problem and is quite common. make a test OU and move the users into it you want your help desk to manage. Right click the OU and select delegate, then give your help desk users the create/delete/manage check box as well as the reset password box if you want them to be able to do that as well.

you can get very granular with the permissions for this kind of stuff. we do this in my environment and it works quite well. check the advanced security after you have delegated the rights to get an idea of what i mean.

kris.
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 11954309
this might work,,, but all of the distribution lists in question would have to be under that OU as well.
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 
LVL 22

Expert Comment

by:kristinaw
ID: 11954360
mike,

distribution lists aren't managed that way. they have a check box that gives the user permission to update group membership. If the box is checked and the appropriate user is filled in in the box, then the user can manage this group no matter where the object is located in AD. If you want help desk users to be able to manage these lists through the ADUC, then you can create a separate OU for them and delegate permissions on the group object under advanced security.

"this might work", it will work. i don't answer questions unless i'm sure of what i'm talking about.

kris.
0
 

Author Comment

by:gaskew
ID: 11954608
Thanks for the quick response
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 11954699
kris,

why are you dogging on me???  FYI ...  ive answered some of your questions in the past

"this might work" what i meant by that is that it would work if it was set up correctly,,, but every environment is different so i never say this WILL work.
0
 
LVL 22

Expert Comment

by:kristinaw
ID: 11956393
mike,

sorry, didn't mean to dog you. but, you can delegate rights to do things only on certain users. kind of one of the big pluses about AD. didn't mean to sound harsh.

have a good one,

Kris.
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Ever visit a website where you spotted a really cool looking Font, yet couldn't figure out which font family it belonged to, or how to get a copy of it for your own use? This article explains the process of doing exactly that, as well as showing how…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question