• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 355
  • Last Modified:

Windows 2003 AD delegation to add new users

Our company has grown to a point we would like to use the ability to delegate someone to add users as well as computers. I ran the delegation wizard, and did a custom selection. When this user logs on, the only options in AD to add are users and computers. Whenever his account creates a new user, in the final step the message "The password for <username> can not be set due to insufficient privleges. Windows will attempt to disable this account." The account then shows up as disabled. Anybody have an idea of what I am missing?
0
Rodney Barnhardt
Asked:
Rodney Barnhardt
  • 3
  • 2
  • 2
1 Solution
 
LauraEHunterMVPCommented:
Off the top of my head, I'd say to run the Delegation Wizard again and grant that same group the ability to reset the user's password.

If that doesn't work, please clarify: what specifically did you delegate in the Delegation Wizard when you selected the custom task option?

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
0
 
stronglineCommented:
why not use the pre-defined "create...manager user account"?

The thing you missed should be "reset password'
0
 
Rodney BarnhardtServer AdministratorAuthor Commented:
I can not find a "reset password". Here is what I am doing:
1. Right clicking on the domain and chosing delegate control
2. Adding the user
3. Selecting "Create Custom Tasks"
4. Selecting "Only allow the following"
5. Selecting "User Objects" and "Computer Objects" and checking both the create and delete boxes on the bottom.
6. Checking all permissions except full control and allowing the wizard to complete.
I scrolled up and down all screens today, and did not see a "reset password" option.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
LauraEHunterMVPCommented:
"Create, Delete and Manage user accounts" and "Reset user passwords and force password change at next logon" are both pre-configured delegations in the wizard.  The following URL will walk you through the steps to delegate one or both of these tasks: http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/directory/activedirectory/stepbystep/ctrlwiz.mspx#ELD
0
 
stronglineCommented:
I guess you misunderstood something here. For user creation, you can use pre-defined tasks in delegation wizard; for computer joining into domain, you define "computer configuration\windows settings\security settings\local policies\user rights assignment\add workstation to domain" in default domain policy. By default everyone can add computer into domain.
0
 
Rodney BarnhardtServer AdministratorAuthor Commented:
Thank you, that link almost has me there since the user can create the account now. The only other issue is since we run AutoCAD, the users need to be in the administrators group on the local machine. While this person can create the account now, there is still an "access denied" when trying to add the user to the administrators local computer group. I have it where they can join the computer to the domain, they can not modify the local administrators account. I looked through the options and tried a few on my test bed, but did not have any luck.
0
 
LauraEHunterMVPCommented:
The user who is creating the account will need to be a local admin on the target workstation.  Best way to do this would be to add your HelpDesk group to the Administrators group using the Restricted Groups function in Group Policy.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

  • 3
  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now