Solved

Delegation read only to certain AD folders

Posted on 2011-09-26
5
367 Views
Last Modified: 2012-05-12
Ok, I know of the delegation wizard, and installing the adminpak.msi for a user you want to delegate certain functions. This is my scenario, I want to give the adminpak to a user to have read only, but on only certain folders/OU's in AD. If the user connects using UAC they connect with no problem with read only. Why, when I have not set any permissions. And is there a best practice for this scenario where to allow certain folders/OU's read only access and others not even able to click on?
I can certainly add the user to each, read on some and deny on others, but this seems a bit much. Any suggestions?
Thanks
0
Comment
Question by:hcalbre
  • 3
  • 2
5 Comments
 
LVL 4

Accepted Solution

by:
mustang83 earned 500 total points
ID: 36601781
Create Taskpads.

http://www.petri.co.il/create_taskpads_for_ad_operations.htm

You can create a task pad that only shows them what you want them to see.
0
 

Author Comment

by:hcalbre
ID: 36602245
Taskpads looks like a user friendly form of the delegation wizard, however, it still does not accomplish what I'm looking for.
I want to load adminpak.msi on a regular users machine and have them connect to AD UAC with read only, but either not see or not be able to open certain OU's. So far, I can only accomplish the disappearing OU's by adding the user to the OU and choosing deny.
In addition, it seems as if nothing is preventing a regular user from adding an mmc snapin of AD UAC and viewing read only, which I find strange.
0
 
LVL 4

Expert Comment

by:mustang83
ID: 36708082
Yes taskpads were designed so you can give normal users certain views that the administrator wants them to see.

Installing adminpak is designed for administrators.  i'd say that what you are trying to do will cause massive administrative overhead.

You can create a taskpad which just tabs all the ou's you want them to have access to. That will solve the only showing them what ou you want.

I beleive all users have read only access to Active Directory UAC so a taskpad is all you need.

Id say you need to create a group policy to stop certain users from playing around with users and computers.
0
 

Author Comment

by:hcalbre
ID: 36710351
Ok, using the MMC method, users by default have read only. How do you make the TaskPad hide certain OU's? Essentially, since read only already exists, I just need to hide a few OU's within the MMC of AD UAC.
0
 
LVL 4

Expert Comment

by:mustang83
ID: 36711846
you cannot hide ous without adding the users to each ou and choosing deny as you described above.

you can right click create new task pad view on every ou you want the users to see.

if there are lots of ous you want them to see, it might get a bit messy.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now