• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 253
  • Last Modified:

RE: Delegation of Administration

I have a question regarding delegation of administration.  Your assistance is greatly appreciated.

If an administrator uses the Delegation of Administration Wizard and assigns certain administrative rights to a user account and/or group over a set of OUs in Active Directory, is there a way for me to view which group or user has been delegated rights and see what those rights are?  I have inherited an AD environment that needs to be cleaned up but I'm not sure if Microsoft has a native tool where I can see this and revoke any rights that a user or group should not have.  Is there a native tool or a third party tool (e.g. Quest Software ActiveRoles) that I can use to manage this?  

Thanks!!

TSB
0
tbaik
Asked:
tbaik
1 Solution
 
oBdACommented:
The tool comes with AD: it's the Active Directory Users and Computers MMC. Just change to Advanced from the View menu, and you'll get a security tab in the properties of the AD objects. From there on, it's basically like NTFS.

Delegate Control Wizard Cannot Be Used to Remove Groups or Users
http://support.microsoft.com/?kbid=229873
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now