Solved

Link or associate Active Directory user accounts to other user accounts ?

Posted on 2010-08-18
4
620 Views
Last Modified: 2012-06-21
We have a Windows Server 2008 domain where we set up new business owners. Often times later on, they'll hire business managers and other staff of their own, and request new email accounts, etc. We create them as seperate accounts, organized into one of 3 OU's. Is there a good way to link or associate AD accounts to other specific AD accounts ? The main problem we're having is that we don't necessarily have a great record of these staff & manager accounts when a business owner terminates or leaves the system, and they become abandoned in our AD.

Thanks!

0
Comment
Question by:budgetblinds
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 4

Accepted Solution

by:
sire_harvey earned 250 total points
ID: 33470585
Several things you can do here. First of all should be a form the Business owners fill out to aquire a new User Account. That way you have a record of users coming in.
Second thing i would do is use the AD User account field "Managed By" and point it at that employee's manager.
Third thing i would do is have a form the Managers fill out when staff / contractors leave. That way you can disable the account and also have a record of the AD change.

It sounds more like a managerial process issue, than an IT issue.
0
 

Author Comment

by:budgetblinds
ID: 33470617
Appreciate the response, but we have forms in place for entering & exiting the system. Again, that only revolves around the business owners; not employees they hire after they are an owener. Legal & the forms only care about the people writing us checks; not their staff.

Was not aware of the "Managed By" capability in 2008 AD. I'll take a look at that. Was hoping for some kind of feature where I could link a few AD accounts together, then where one of the accounts couldn't be deleted without un-linking or deleting the other accounts as well.

Thanks
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 250 total points
ID: 33470697
After reading your response no way that I know of to do what you want  (can't delete User Object A unless User Account B is deleted first)

There are tools to try and identify old/abandoned accounts

Old computer by Joe Richards is a good one

http://www.joeware.net/freetools/tools/oldcmp/index.htm

Works with users with the -users switch.

We use it for computers and users.  We disable after 120 days and delete after 180.

Thanks

Mike
0
 

Author Closing Comment

by:budgetblinds
ID: 33591550
Seems unfortunately there is no way to do exactly what we were hoping. Thanks for the suggestions.
0

Featured Post

Forrester Webinar: xMatters Delivers 261% ROI

Guest speaker Dean Davison, Forrester Principal Consultant, explains how a Fortune 500 communication company using xMatters found these results: Achieved a 261% ROI, Experienced $753,280 in net present value benefits over 3 years and Reduced MTTR by 91% for tier 1 incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This article will help to fix the below errors for MS Exchange Server 2013 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question