Link to home
Start Free TrialLog in
Avatar of ENTPF
ENTPF

asked on

Hide OUs in Active Directory Users and Computers

I want to delegate permissions to an admin in Active Directory Users and Computers.  I also don't want the admin to see any other containers than the one that is being delegated to him.  Is this possible?
Avatar of DenverRick
DenverRick

No.  You can prevent the access by him but he will still see the the containers.  There is no "hidden" feature like there is for Folder shares.
Actually it is possible, but -extremely- non-trivial. By default, the Authenticated Users group has Read access to nearly the entire directory. You can remove this permission at the domain level and assign Read permissions manually at lower OU levels, but it needs to be carefully tested in a lab environment before deploying to production, as it has the potentical to break a -lot- of applications, including Group Policy.
Totally unsupported.
Totally incorrect - google "Confidentiality bit" for some examples, or come to the Directory Experts Conference most years to listen to Guido Grillenmeier or someone else from HP present on it.  Any number of organizations have implemented it, but it is absolutely something that must be done with care and with significant testing.
ASKER CERTIFIED SOLUTION
Avatar of minvis
minvis
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The "Acceptde Solution" is is not completely correct infact if a domain user install Windows Server 2003 Administration Tools Pack or RSAT can see all ad ou, users, ou and computers.
Hi,

Datoga comment is right, unless you can program youself special tools, having delegation does not mean that all other OUs and it contents are hidden from the user. They just not be able to change/delete it.

-khairil-