[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Rights Delegation in AD

Posted on 2006-05-17
2
Medium Priority
?
673 Views
Last Modified: 2010-08-05
How can I delegate the rights to reset passwords & unlock user account to a specific group on a specific OU.

thanks
0
Comment
Question by:inf2300
  • 2
2 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 2000 total points
ID: 16699757
Active Directory Delegation of Control

There are times when you want to give a particular user/group, rights to do mundane tasks
like unlock accounts reset passwords etc but you DONT (for obvious reasons) want to put
them in the domain admins group. The simplest solution is to put the users into the "account
operators" group, the drawback of this is they then have those rights across the ENTIRE DOMAIN.

A more practical solution is to use the built in delegation of control wizard, for example
if your finance department want a user or group of users to be able to manage THEIR user
accounts only then simply create a finance OU (organisational Unit) in active directory
(in AD users and computers > right click [yourdomain] > new > Organisational unit)

Move the user objects into this OU (select the user(s) right click >move)

Decide weather its an individual user you want to grant rights to or a group of users. If
its a group create a group (in the OU you created) and put in the users who need the rights.

Now simply right click the new OU and select "Delegate control" follow the on screen wizard
and give the appropriate rights to the group or user.

Delegation of Control
http://www.windowsitpro.com/SmallBusinessCenter/Article/ArticleID/22555/SmallBusinessCenter_22555.html

Step-by-Step Guide to Using the Delegation of Control Wizard
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/ctrlwiz.mspx
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 16854238
Thanq
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question