AD delegation question/problem

Posted on 2004-10-28
Last Modified: 2013-12-04
Question about delgating rights to an OU in Active Directory.  I delegated rights to XYZ user to create/delete computer object to this object and all child objects in an OU.  XYZ user can create and delete computer objects that it creates.  The problem that I am having is that if another user creates a computer object in the same OU, XYZ can't delete or reset the computer account.  

Question by:kck7
    1 Comment
    LVL 16

    Accepted Solution

    This is because you didn't enforce inheritance.

    In AD Users and computer tool, click view and advanced features
    Rightclick on the OU you have delegated access to and select properties
    In the security tab, press advanced and select the check box at the bottom of the dialog that refers to "Allow inheritable permissions..."

    This will ensure that each NEW object that is created will inherit the rights from the OU container itself - so provided you have configred the rights correctly user XYZ will automatically get the rights over the new objects.



    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    First let me explain that I am extremely paranoid about computer security issues and computer backup issues.  This means that I only feel safe if I am running unknown programs and visiting unknown sites in a virtual machine.  In that way, if anythin…
    Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
    This video Micro Tutorial is the second in a two-part series that shows how to create and use custom scanning profiles in Nuance's PaperPort 14.5 ( But the ability to create custom scanning profiles a…
    how to add IIS SMTP to handle application/Scanner relays into office 365.

    913 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now