?
Solved

How do I let admins only delete the OUs they created?

Posted on 2007-04-03
2
Medium Priority
?
193 Views
Last Modified: 2013-12-04
Hi
I'm trying to get a controlled AD designed & implemented, but I'm running into a few problems with delete rights in a Windows 2003 AD.

My situation is this: Each physical branch office is going to relate to an OU in the AD. There will be a parent OU, lets call it MASTER, with an OU for each branch office, so let's say OU1, OU2, OU3, and OU4. That's the default set of OUs each branch will receive. I want to delegate so that the each branch admin can, if they so desire, either create more new OUs directly in the branch OU, or create more new OUs in one of either OU1, OU2, OU3, or OU4. I want them to be able to delete whatever they have created themselves, but I **DONT** want them to create any of the defaut set (OU1/2/3/4). I've tried assigning various permutations, such as allowing full control on the branch OU, but explicit deny permissions on the standard OU set, but nothing seems to work because of the way Windows 2003 processes the inherited vs explicit permissions set.

Its proving very annoying!

Thanks for your help
0
Comment
Question by:tbennett35
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 1000 total points
ID: 18843677
Go to the Properties tab of OU1, OU2, OU3, OU4. Click Advanced from the Security tab and look for the option to configure security settings that apply to "Child objects only" - this will confer rights to create objects underneath Ou1/2/3/4 without the user having rights to modify or delete the OU itself.  You'll have to do this 4 times, once for each of ou1/2/3/4.

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
0
 

Author Comment

by:tbennett35
ID: 18843955
Laura Hunter...well well well...I bought your book!

Got to hand it to you...that must probably be about the only thing I didn't try, because I was ripping my hair out yesterday! It worked a treat!
0

Featured Post

Need protection from advanced malware attacks?

Look no further than WatchGuard's Total Security Suite, providing defense in depth against today's most headlining attacks like Petya 2.0 and WannaCry. Keep your organization out of the news with protection from known and unknown threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses
Course of the Month12 days, 15 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question