Link to home
Start Free TrialLog in
Avatar of Simon336697
Simon336697Flag for Australia

asked on

Granting a user account a specific right (to edit an existing AD attribute for any user

Hi guys,
I hope you are all well.
Guys, we have a requirement where we want a user called 'Bob', to be able to edit an Active Directory attribute. That attribute is an existing AD attribute called 'primaryTelexNumber'. We dont want to give him domain admin access just to perform this task, so we want to give him the minimal rights required to perform this operation.
Basically, when a new user comes on, Bob needs to be able to change the primaryTelexNumber attribute for this user.
So, we are not extending the schema, we just want to provide Bob with the rights to perform this operation but not give him any more rights than required.

Thanks guys.
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

Please read article on my blog for AD rights delegation and try to accomplish that using hints there. Look on the list for this attribute primaryTelexNumber and select appropriate Write/Read rights

Avatar of Simon336697


Hi Krzysztof, thanks so much, you are obviously very very knowledgeable.
Krzysztof, Im still not entirely sure how to select the attribute primaryTelexNumber and which tool I use to select it.
I know that this attribute is a common attribute attached to a standard user account.
If I want Bob to have the ability to change just this attribute, and to have this ability for ALL users, how do I give this without having to do this everytime a new user comes on board?
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi KrZ,
Thanks so much for your help.