?
Solved

Give HR Employees Access to Edit Active Directory Info

Posted on 2011-02-25
2
Medium Priority
?
2,367 Views
Last Modified: 2012-06-21
What is the best method to give our HR employees access to edit some minor Active Directory information in our AD 2003 Environment? We would primarily like them to edit the Organization tab to update our organizational structures.

Also - once access is granted, what is the best tools/utilities to load on their computers so that they may edit AD info?

Thank you -
0
Comment
Question by:RavenInd
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 12

Assisted Solution

by:Navdeep
Navdeep earned 800 total points
ID: 34983992
Hi,

You can create a security group and then use "Delegate Control" to give required level of control to modify and update Organization Tab Attribute.

Users can use Adminpack, or just the directory services users and computers snapin to update the changes.
0
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 1200 total points
ID: 34994067
I would also agree with v-2nas that delegation of permissions is the way to go.

Give this a quick read through for the basics. If you have any specific questions post back.
http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html

As far as what tool to manage the users the HR employees will be using the acitve directory users and computers snap in to modify the accounts. However depending on how you have your OU structure configured you may be able to go even one step further and create a custom MMC for them.

This custom MMC can be useful if all of your user accounts are in the same OU. You can set this MMC to only open to that location and they will not be able to even browse the other OUs.

http://www.petri.co.il/create_taskpads_for_ad_operations.htm

A little more info on the custom MMC
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question