Avatar of Simon336697
Flag for Australia asked on

Granting a user account a specific right (to edit an existing AD attribute for any user

Hi guys,
I hope you are all well.
Guys, we have a requirement where we want a user called 'Bob', to be able to edit an Active Directory attribute. That attribute is an existing AD attribute called 'primaryTelexNumber'. We dont want to give him domain admin access just to perform this task, so we want to give him the minimal rights required to perform this operation.
Basically, when a new user comes on, Bob needs to be able to change the primaryTelexNumber attribute for this user.
So, we are not extending the schema, we just want to provide Bob with the rights to perform this operation but not give him any more rights than required.

Thanks guys.
Shell ScriptingActive Directory

Avatar of undefined
Last Comment

8/22/2022 - Mon
Krzysztof Pytko

Please read article on my blog for AD rights delegation and try to accomplish that using hints there. Look on the list for this attribute primaryTelexNumber and select appropriate Write/Read rights


Hi Krzysztof, thanks so much, you are obviously very very knowledgeable.
Krzysztof, Im still not entirely sure how to select the attribute primaryTelexNumber and which tool I use to select it.
I know that this attribute is a common attribute attached to a standard user account.
If I want Bob to have the ability to change just this attribute, and to have this ability for ALL users, how do I give this without having to do this everytime a new user comes on board?
Krzysztof Pytko

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

Hi KrZ,
Thanks so much for your help.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes