[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How do I create a custom "AD users and computers" that only allows changing of passwords and unlocking accounts

Posted on 2009-02-20
4
Medium Priority
?
223 Views
Last Modified: 2012-05-06
I want to create an interface to allow CSRs to unlock Active Directory accounts.  I don't want to install the Admin Pak as the "Account Operators Group" will give them too much power.
0
Comment
Question by:daverdal
1 Comment
 
LVL 58

Accepted Solution

by:
tigermatt earned 1000 total points
ID: 23698953
You'd first have to delegate the appropriate permissions over the OUs the users need control on. This is achieved using the Delegation of Control wizard. http://www.windowsnetworking.com/kbase/WindowsTips/Windows2000/AdminTips/Miscellaneous/UsingtheDelegationofControlWizardStep-by-step.html

Once you've done that, in order to create a custom view, you'd need to create an Active Directory Taskpad. This allows you to specify default operations in the MMC view which the users have quick access to: http://windowsitpro.com/article/articleid/25346/how-can-i-create-a-taskpad-in-a-windows-xp-microsoft-management-console-mmc-console.html

-Matt
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question