Solved

AD Users and computers snap in from Client Machine

Posted on 2006-07-04
3
648 Views
Last Modified: 2008-02-07
hi all,
   I'm delegating some AD responsibility to some users and i want to know how to give them access to AD to perform the delegated tasks. I know you have to ins tall Windows 2003 admin tools for them to have AD mmc available.

Is there a way around that. I dont want users to access any other tools in the admin tool and preferably i dont want them to even see other containers than the one they are delegated for.

Any ideas on how to give them access to AD without installing Admin tools. Also is there a way to prevent them from seeing other containers...

Vinod.
0
Comment
Question by:mvvinod
  • 2
3 Comments
 
LVL 29

Expert Comment

by:mass2612
ID: 17040007
Hi,

Install the tools and then delete or rename the mmc and exe files for the other tools. You can't hide the other containers within AD. MS hasn't caught on to that yet as far as I know. If they don't have any permissions they shouldn't you won't need to be concerned about them seeing anything they could break.
0
 
LVL 26

Accepted Solution

by:
Pber earned 250 total points
ID: 17041862
To install just the AD tools from the adminpak just do this:
msiexec /i adminpak.msi ADDLOCAL=FeADTools /qb

The default AD MMC's will not allow you to prevent users from seeing other OU's.  Some 3rd party products have this ability to only show users what they've been delegated.  This is usually done through a WEB interface.  Quest has a good product called ActiveRoles Direct or ActiveRoles Server: http://www.quest.com/activeroles_server/

0
 
LVL 29

Assisted Solution

by:mass2612
mass2612 earned 250 total points
ID: 17041911
Thanks Pber - good article for this here - http://support.microsoft.com/?kbid=314978
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

Suggested Solutions

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now