Delegating Control is Gray Out

Posted on 2004-11-29
Last Modified: 2010-04-14
Okay. Here is my setup.

I have two domain controlers using the same name  Replication works find.  I delegated control to a jr. administrator.  I logon as the Jr. Administrator and try to change the password and I get an access deny.  No matter what I try, I can get this jr. adminstrator to delegate his own OU.

What Am I doing wrong?

Question by:lrodriguez
    LVL 11

    Expert Comment

    Did you make sure that you ran Delegate Control from the OU that the user accounts are in?

    Author Comment

    Thanks for the fast response.

    Yes, I am applying delegation at the OU.  Then I logon on as the user whom I delegated control to.  I go to the OU and I notice that I can reset passwords, add users, add groups, etc for any of the users in the OU.  But I can't change any of the settings for the user I gave control to.  All the attributes for this Help Desk Admin are gray out.  Is this normal?

    Is it safe to say, the following is true?  

    When I delegate control to the Help Desk Admin at his OU, as the administrator I control what that Help Desk Admin can do.  And then the Help Desk Admin controls the objects within his OU, but can not contol his account due to the fact that he is under my control?  Hope this makes sense.


    Luis M. Rodriguez, MCP.
    LVL 11

    Expert Comment

    Hello Luis,

    Is the admin located in the OU that he is delegated control over?

    Author Comment

    Yes the Help Desk Admin is part of the OU.  There are a tool of 18 users in the OU, but I can not change any of the settings for the Help Desk Admin.  Is this normal or am I doing someting wrong?
    LVL 11

    Accepted Solution

    I've heard that this is normal because you don't want the help desk admin to add himself to a more powerful group.  I think you have to move him out of the OU for him to control himself.  I'll try to find some documentation to confirm.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    Suggested Solutions

    NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
    When we have a dead host and we lose all connections to the ESXi, and we need to find a way to move all VMs from that dead ESXi host.
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now