Solved

Give HR Employees Access to Edit Active Directory Info

Posted on 2011-02-25
2
2,294 Views
Last Modified: 2012-06-21
What is the best method to give our HR employees access to edit some minor Active Directory information in our AD 2003 Environment? We would primarily like them to edit the Organization tab to update our organizational structures.

Also - once access is granted, what is the best tools/utilities to load on their computers so that they may edit AD info?

Thank you -
0
Comment
Question by:RavenInd
2 Comments
 
LVL 12

Assisted Solution

by:Navdeep
Navdeep earned 200 total points
ID: 34983992
Hi,

You can create a security group and then use "Delegate Control" to give required level of control to modify and update Organization Tab Attribute.

Users can use Adminpack, or just the directory services users and computers snapin to update the changes.
0
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 300 total points
ID: 34994067
I would also agree with v-2nas that delegation of permissions is the way to go.

Give this a quick read through for the basics. If you have any specific questions post back.
http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html

As far as what tool to manage the users the HR employees will be using the acitve directory users and computers snap in to modify the accounts. However depending on how you have your OU structure configured you may be able to go even one step further and create a custom MMC for them.

This custom MMC can be useful if all of your user accounts are in the same OU. You can set this MMC to only open to that location and they will not be able to even browse the other OUs.

http://www.petri.co.il/create_taskpads_for_ad_operations.htm

A little more info on the custom MMC
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question