Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Delegate OU In Adtive Directory in windows 2003 server.

Posted on 2007-11-23
8
Medium Priority
?
538 Views
Last Modified: 2009-06-23
Hello everybody,
I've just delegated an ou for an user in Adtive Directory in Windows 2003 server by right click the ou and then select the delegate control. It is ok. Now I want to cancel this task, I want to undelegate that OU for the user. How can I do? Please guide me step by step. Thanks.
0
Comment
Question by:diamondhead
8 Comments
 
LVL 11

Expert Comment

by:bsharath
ID: 20341839
Download Active administrator from Scriptlogic website.I think this is the only way to see the delegations and remove them...
0
 
LVL 70

Accepted Solution

by:
KCTS earned 100 total points
ID: 20342146
There is noi simple wizard to undo a delegation, You need to go to "Active Directory Users and Computers" and make sure that  "View", "Advanced features" is selected

Right click on the OU that you delegated and click the security tab, you should see the account that you delegated to. Remove the account from the ACL to cancel the delegtion (or you can modify the permissions).
0
 
LVL 3

Expert Comment

by:l84work
ID: 20345076
KCTS is 100% correct!  

Sounds like you are not familiar with this process.  Be careful not to remove some of the default permissions, you don't want to lock out other users or even yourself.  And be careful with DENY permission, it overwrites everything else.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 30

Assisted Solution

by:LauraEHunterMVP
LauraEHunterMVP earned 100 total points
ID: 20347828
bsharath is entirely incorrect - third-party software is in no way a requirement to view and remove security delegations within AD. KCTS's instructions will point you in the correct direction.  If you have multiple delegations to undo (it sounds like you only have one but just in case) you can also use the dsrevoke command-line tool available here: http://www.microsoft.com/downloads/details.aspx?familyid=77744807-c403-4bda-b0e4-c2093b8d6383
0
 
LVL 11

Expert Comment

by:bsharath
ID: 20347978
LauraEHunterMVP
I am sorry if i am wrong as i once was told that it was the only way by experts in EE. And when i wanted to find delegations i found the third party software very easy to find.
I tried dsrevoke but did not get the results...
The software is easy to click on each OU to find the delegated users....
0
 
LVL 3

Expert Comment

by:l84work
ID: 20348020
Laura is correct, 3rd software is not a REQUIREMENT.

As for 3rd party software, I've used ScriptLogic before.  It does have a user friendly interface.  But personally, I think Hyenas 7.1 (http://www.systemtools.com/hyena/hyena_new.htm) is better.
0
 

Author Comment

by:diamondhead
ID: 20348201
Hello Everybody,
Thanks for your instruction. Now it's ok.  I have just done via the KCTS guides.  And I don't try with The third party software. Thanks again and Have a nice day.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question