Solved

Delegation Control- Checking permissions and getting it working with new updates

Posted on 2008-06-16
1
239 Views
Last Modified: 2012-05-05
We have a windows SBS Server 2003, with WSUS 3.1 installed. Previously we had delegated the sysadmin to take control over one Organizational Unit so he could take control over resetting of the passwords of the users in that particular OU. This seem to work all fine with ADMIN PACK 2003 installed on his machines until his machine and the server both were updates using the WSUS Server. His machine has now got XP SP3. Here are the 2 issues I am trying to solve -

1. The user that was delegated control can no longer reset passwords or disable/enable accounts for that OU. When he tried to do that, he gets an error saying - "Windows cannot disable object "%username%" because: insufficient access rights to perform the operation".
I have reassigned the delegation rights on that OU a couple of times with no luck. Also I have tried uninstalling and re-installing the admin pack on that machine.

2. I have checked the user permissions using ACL DIAG tool and the sys admin has got all the delegated permissions needed. What else can be the problem??

Also I just noted that he can create new users but cannot modify properties on existing user objects.
0
Comment
Question by:easynet07
1 Comment
 
LVL 70

Accepted Solution

by:
KCTS earned 500 total points
ID: 21798380
Make sure that there is no explicit DENY for the user
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now