Rights Delegation in AD

Posted on 2006-05-17
Last Modified: 2010-08-05
How can I delegate the rights to reset passwords & unlock user account to a specific group on a specific OU.

Question by:inf2300
    LVL 57

    Accepted Solution

    Active Directory Delegation of Control

    There are times when you want to give a particular user/group, rights to do mundane tasks
    like unlock accounts reset passwords etc but you DONT (for obvious reasons) want to put
    them in the domain admins group. The simplest solution is to put the users into the "account
    operators" group, the drawback of this is they then have those rights across the ENTIRE DOMAIN.

    A more practical solution is to use the built in delegation of control wizard, for example
    if your finance department want a user or group of users to be able to manage THEIR user
    accounts only then simply create a finance OU (organisational Unit) in active directory
    (in AD users and computers > right click [yourdomain] > new > Organisational unit)

    Move the user objects into this OU (select the user(s) right click >move)

    Decide weather its an individual user you want to grant rights to or a group of users. If
    its a group create a group (in the OU you created) and put in the users who need the rights.

    Now simply right click the new OU and select "Delegate control" follow the on screen wizard
    and give the appropriate rights to the group or user.

    Delegation of Control

    Step-by-Step Guide to Using the Delegation of Control Wizard
    LVL 57

    Expert Comment

    by:Pete Long

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Join & Write a Comment

    Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
    I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    24 Experts available now in Live!

    Get 1:1 Help Now