Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Allow limited edits to active directory

Posted on 2012-03-22
2
Medium Priority
?
417 Views
Last Modified: 2012-03-22
Our HR department is requesting access to edit users in active directory.  I have no issue with this, but I want to restrict them to certain fields.  They should only be able to edit the address, telephone and organization tabs.  It would also be nice if they could edit a few fields on the general tab.

I know how to delegate permissions to users/groups in AD.  I just can't figure out how to restrict access to what I just explained.  Is this possible?
0
Comment
Question by:PC2009
2 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 37754667
You have to give them rights to just those attributes.  They would also still have to use ADUC to edit.  

Do they already have an HR database?

I'd think about a third party (or build your own) front end, something like directory manager

http://www.ithicos.com/

Thanks

Mike
0
 

Author Comment

by:PC2009
ID: 37754728
Yea, I think you're right.  A 3rd party would be much easier for non-IT people to navigate.  I will take a look at ithicos and a few others.  Thanks for the input!
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question