Solved

Need to grant specific rights to computer objects in AD

Posted on 2010-11-16
3
405 Views
Last Modified: 2012-06-27
I am trying to come up with a way to allow Help Desk staff to Add/Remove/Move Computer objects in AD.By move I mean move from one OU to another. I was looking at the Delegation Wizard in ADUC but could not figure it out. I want just these rights and nothing else so if I add a Help Desk member to a group I delegated rights to, that is all they can do.
0
Comment
Question by:osiexchange
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 27

Expert Comment

by:KenMcF
ID: 34148752
You can follow the steps in this link to allow them to add the computers to the doamin. I would recommend creating a secuirty group and adding the group to the GPO.  Then add all your help desk users to that group.

http://www.windowsitpro.com/article/domains2/jsi-tip-8144-how-can-i-allow-an-ordinary-user-to-add-a-computer-to-a-domain-.aspx
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 34148773
You will probably have to go granular into the ACL (not a default choice in the delegation control wizard)  

http://support.microsoft.com/kb/818091
 
You can extend the delegation control wizard   http://adisfun.blogspot.com/2009/08/extend-ad-delegation-control-wizard.html

...not at my lab right now so not sure if move computer objects is one that is added there.

Thanks
Mike
0
 

Author Comment

by:osiexchange
ID: 34149190
The newer inf file does add a lot of rights from the default but I did not see anythingi in there about moving a computer object. The miicrosoft article seems to cover moving and removing but not adding.

Do you know if chaniging the inf file does anything to rights already delegated using the old inf file?
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

689 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question