?
Solved

Delegatin Control does now work at Site.

Posted on 2004-11-17
2
Medium Priority
?
176 Views
Last Modified: 2010-04-14
Hello,

I just recently added an additional domain controller at one of my remote sites, (SAME DOMAIN).  I populated an OU with Users, Printers and Computers (NO GROUPS).  And finally, delegated Control to a junior administrator to control "Reset Passwords only".

But when the junior administrator, logs on to the Domain Controller using his user ID and Password, he is still able to add users, printers and create OU's within his OU and all the others OU's within the Domain.    

What I am doing wrong?  I only want the Jr. Administrator to reset passwords for his OU only!

P.S.  Site replaication is working correctly.

Luis M. Rodriguez, MCP.
0
Comment
Question by:lrodriguez
2 Comments
 
LVL 9

Accepted Solution

by:
jamesreddy earned 1420 total points
ID: 12605312
Take him out of the administrators group.....and add him to the list of users with permissions to log on locally.  If he is a member of the administrators group or domain admins, he will have full administrative privelages.  You need to keep him in Domain Users, give him local logon rights, then assign the policy setting to reset passwords.
0
 
LVL 20

Expert Comment

by:Debsyl99
ID: 12605597
Hi
Might be better to put him in his own security group, make that group member of domain users, do the rest that jamesreddy suggested and then use delegation of control to delegate to that security group. You can then just move him out and someone else in should you ever wish to.

0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
You have missed a phone call. The number looks like it belongs to the bunch of numbers which your company uses. How to find out who has just called you?
Enter Foreign and Special Characters Enter characters you can't find on a keyboard using its ASCII code ... and learn how to make a handy reference for yourself using Excel ~ Use these codes in any Windows application! ... whether it is a Micr…
Free Data Recovery software is an advanced solution from Kernel Tools to recover data and files such as documents, emails, database, media and pictures, etc. It supports recovery from physical & logical drive after a hard disk crash, accidental/inte…
Suggested Courses

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question