How to grand user right to add or remove user in AD?

Posted on 2007-08-03
Last Modified: 2013-12-04
Is there a add on I can use to allow regular user to create user account in Active Directory? I don't want to put the user in domian admin group but she needs to have the ability of creating new users. Any suggestion would be helpful!

Question by:changjia
    LVL 6

    Expert Comment

    Here is a web-page with some information for delegating authority.
    LVL 70

    Accepted Solution

    if you want to do this for the domain then open up Active Directory users and Computers, right click and select Delegate Control. This will launce the Delegation of control wizard and you canuse this to delegate the necessary permissions to the user (really you should put the user in a group and then delegate to the group  - this will make it much easier to add other users and/or revoke the delegation in the future.

    Once that has been done then, assuming that you want the other user to be able to create accounts without logging on to the domain controller you can add the administrative tools to the users PC.

    Log on to the users PC and connect to \\servername\%systemroot%\System32
    Find and run AdminPak.msi and install the tools. This will install all the admin tools on the local PC but the user will only be able to run the once for which you have delegated permission.

    If you want to make it even simpler for the user you can create a taskpad with just the required tasks
    LVL 27

    Expert Comment

    by:Jason Watkins
    You could also add the user to the "Account Operators" group in AD.
    LVL 70

    Expert Comment

    Adding a user to the Account Operators Group would give additional rights including management of group and computers and the ability to log on to the DC and shutdown the system.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
    Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
    This video discusses moving either the default database or any database to a new volume.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    14 Experts available now in Live!

    Get 1:1 Help Now