Simon336697
asked on
Granting a user account a specific right (to edit an existing AD attribute for any user
Hi guys,
I hope you are all well.
Guys, we have a requirement where we want a user called 'Bob', to be able to edit an Active Directory attribute. That attribute is an existing AD attribute called 'primaryTelexNumber'. We dont want to give him domain admin access just to perform this task, so we want to give him the minimal rights required to perform this operation.
Basically, when a new user comes on, Bob needs to be able to change the primaryTelexNumber attribute for this user.
So, we are not extending the schema, we just want to provide Bob with the rights to perform this operation but not give him any more rights than required.
Thanks guys.
I hope you are all well.
Guys, we have a requirement where we want a user called 'Bob', to be able to edit an Active Directory attribute. That attribute is an existing AD attribute called 'primaryTelexNumber'. We dont want to give him domain admin access just to perform this task, so we want to give him the minimal rights required to perform this operation.
Basically, when a new user comes on, Bob needs to be able to change the primaryTelexNumber attribute for this user.
So, we are not extending the schema, we just want to provide Bob with the rights to perform this operation but not give him any more rights than required.
Thanks guys.
ASKER
Hi Krzysztof, thanks so much, you are obviously very very knowledgeable.
Krzysztof, Im still not entirely sure how to select the attribute primaryTelexNumber and which tool I use to select it.
I know that this attribute is a common attribute attached to a standard user account.
If I want Bob to have the ability to change just this attribute, and to have this ability for ALL users, how do I give this without having to do this everytime a new user comes on board?
Krzysztof, Im still not entirely sure how to select the attribute primaryTelexNumber and which tool I use to select it.
I know that this attribute is a common attribute attached to a standard user account.
If I want Bob to have the ability to change just this attribute, and to have this ability for ALL users, how do I give this without having to do this everytime a new user comes on board?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi KrZ,
Thanks so much for your help.
Thanks so much for your help.
http://kpytko.wordpress.com/2012/05/16/active-directory-rights-delegation-overview/
http://kpytko.wordpress.com/2012/05/17/active-directory-rights-delegation-part-1/
Regards,
Krzysztof