[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Delegate user to disable user account only Windows 2008 R2

Posted on 2010-11-15
3
Medium Priority
?
1,740 Views
Last Modified: 2012-05-10
I have modified a scipt that I fould that allows a user to enable/disable a user account, the script works great , no errors. Heres my problem, I need to allow store managers to disable user accounts for our their store and only disable the account.
I have set up an OU for each store and delagateed the store manager to that OU, but hte only option the wizrad allows that is even close is to create/delete and change a user. I do not want to give my managers that much access. How do I only allow them to disable an account for their OU?
0
Comment
Question by:TheonWier
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34138521
You need to give them access to useraccountcontrol Brian Desmond has a good blog post on how to do this.

http://briandesmond.com/blog/delegating-enable-disable-account-rights-in-active-directory/
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34143143
0
 

Author Closing Comment

by:TheonWier
ID: 34284526
not the answer I was looking for
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question