Solved

Allow limited edits to active directory

Posted on 2012-03-22
2
409 Views
Last Modified: 2012-03-22
Our HR department is requesting access to edit users in active directory.  I have no issue with this, but I want to restrict them to certain fields.  They should only be able to edit the address, telephone and organization tabs.  It would also be nice if they could edit a few fields on the general tab.

I know how to delegate permissions to users/groups in AD.  I just can't figure out how to restrict access to what I just explained.  Is this possible?
0
Comment
Question by:PC2009
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 37754667
You have to give them rights to just those attributes.  They would also still have to use ADUC to edit.  

Do they already have an HR database?

I'd think about a third party (or build your own) front end, something like directory manager

http://www.ithicos.com/

Thanks

Mike
0
 

Author Comment

by:PC2009
ID: 37754728
Yea, I think you're right.  A 3rd party would be much easier for non-IT people to navigate.  I will take a look at ithicos and a few others.  Thanks for the input!
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article runs through the process of deploying a single EXE application selectively to a group of user.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question