?
Solved

Give HR Employees Access to Edit Active Directory Info

Posted on 2011-02-25
2
Medium Priority
?
2,420 Views
Last Modified: 2012-06-21
What is the best method to give our HR employees access to edit some minor Active Directory information in our AD 2003 Environment? We would primarily like them to edit the Organization tab to update our organizational structures.

Also - once access is granted, what is the best tools/utilities to load on their computers so that they may edit AD info?

Thank you -
0
Comment
Question by:RavenInd
2 Comments
 
LVL 12

Assisted Solution

by:Navdeep
Navdeep earned 800 total points
ID: 34983992
Hi,

You can create a security group and then use "Delegate Control" to give required level of control to modify and update Organization Tab Attribute.

Users can use Adminpack, or just the directory services users and computers snapin to update the changes.
0
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 1200 total points
ID: 34994067
I would also agree with v-2nas that delegation of permissions is the way to go.

Give this a quick read through for the basics. If you have any specific questions post back.
http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html

As far as what tool to manage the users the HR employees will be using the acitve directory users and computers snap in to modify the accounts. However depending on how you have your OU structure configured you may be able to go even one step further and create a custom MMC for them.

This custom MMC can be useful if all of your user accounts are in the same OU. You can set this MMC to only open to that location and they will not be able to even browse the other OUs.

http://www.petri.co.il/create_taskpads_for_ad_operations.htm

A little more info on the custom MMC
0

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
I’m willing to make a bet that your organization stores sensitive data in your Windows File Servers; files and folders that you really don’t want making it into the wrong hands.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question