Solved

Link or associate Active Directory user accounts to other user accounts ?

Posted on 2010-08-18
4
618 Views
Last Modified: 2012-06-21
We have a Windows Server 2008 domain where we set up new business owners. Often times later on, they'll hire business managers and other staff of their own, and request new email accounts, etc. We create them as seperate accounts, organized into one of 3 OU's. Is there a good way to link or associate AD accounts to other specific AD accounts ? The main problem we're having is that we don't necessarily have a great record of these staff & manager accounts when a business owner terminates or leaves the system, and they become abandoned in our AD.

Thanks!

0
Comment
Question by:budgetblinds
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
sire_harvey earned 250 total points
ID: 33470585
Several things you can do here. First of all should be a form the Business owners fill out to aquire a new User Account. That way you have a record of users coming in.
Second thing i would do is use the AD User account field "Managed By" and point it at that employee's manager.
Third thing i would do is have a form the Managers fill out when staff / contractors leave. That way you can disable the account and also have a record of the AD change.

It sounds more like a managerial process issue, than an IT issue.
0
 

Author Comment

by:budgetblinds
ID: 33470617
Appreciate the response, but we have forms in place for entering & exiting the system. Again, that only revolves around the business owners; not employees they hire after they are an owener. Legal & the forms only care about the people writing us checks; not their staff.

Was not aware of the "Managed By" capability in 2008 AD. I'll take a look at that. Was hoping for some kind of feature where I could link a few AD accounts together, then where one of the accounts couldn't be deleted without un-linking or deleting the other accounts as well.

Thanks
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 250 total points
ID: 33470697
After reading your response no way that I know of to do what you want  (can't delete User Object A unless User Account B is deleted first)

There are tools to try and identify old/abandoned accounts

Old computer by Joe Richards is a good one

http://www.joeware.net/freetools/tools/oldcmp/index.htm

Works with users with the -users switch.

We use it for computers and users.  We disable after 120 days and delete after 180.

Thanks

Mike
0
 

Author Closing Comment

by:budgetblinds
ID: 33591550
Seems unfortunately there is no way to do exactly what we were hoping. Thanks for the suggestions.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question