Solved

Help - How do I create a OU Admin? But it cannot has rights to the other OU's!

Posted on 2008-10-02
5
347 Views
Last Modified: 2009-01-15
I have Enterprise Admin Rights, and I have many people that want to do things all the time with there own OU. That is OK, but I want to control and have those individual manage there own OU's.

I know, Deligate! and I have read that but how to maintain those boundrys - some similar Active Directory for Dummies explains a little and they are close but far from my requirements above.

Either OU admin's, must not have the rights or power to do anything in each others OU, Except for the OU manger or OU Admin what ever you want to call him...  
0
Comment
Question by:mark_randolph
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 5

Expert Comment

by:ostaehr
ID: 22628040
As you said: delegate. Create a global group for an OU and grant some administrative rights on this OU to the group. Put regular users (NOT domain-admins) into this group and you're done. Repeat for each OU.
Yes, this is a bunch of work to do.
0
 
LVL 4

Expert Comment

by:lscapa
ID: 22633798
Continuing ostaehr's comment a little. When your in the delegation wizard just select "custom task" -> This folder, existing objects in this folder and creation" -> Under permissions select "Full Control".
Now this will give that group full control over every object in the OU and any OU underneath this point. If you're wanting ot grant only specific tasks to these individuals then that needs a different approach.
0
 
LVL 1

Author Comment

by:mark_randolph
ID: 22635552
So Iscapa, If I understand you correctly, when you give full control to every object in the OU does that also give you permission to add computers to that OU as well?

Ostaehr - That was so uninformative, next time I would recommend that you provide a little spice with your answers.
I know your trying to help, but please be a little more discriptive.
0
 
LVL 4

Accepted Solution

by:
lscapa earned 500 total points
ID: 22635575
Yes it does. EVERY OBJECT is included with Full Control.
0
 
LVL 1

Author Comment

by:mark_randolph
ID: 22635659
Let me try that, and if it works I will give you the accepted solution provider...
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
A hard and fast method for reducing Active Directory Administrators members.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question