troubleshooting Question

User Delegation of Control in Server 2008 R2 Active Directory

Avatar of sedberg1
sedberg1 asked on
Active DirectoryWindows Server 2008
6 Comments1 Solution1025 ViewsLast Modified:
I'm trying to delegate permissions to a help desk group so they can create new users and modify particular groups.  My OU structure looks like this:

- Admins OU
- Admins OU/Tech Support OU - actual users for helpdesk group, everyone is part of helpdesk group
- Admins OU/Groups OU - contains the helpdesk security group
- Accounting OU
- Accounting OU/Users OU - actual accounting users, everyone is part of acctgusers security group
- Accounting OU/Groups OU - contains the acctgusers group

So, I right-clicked the Accounting OU/Users OU, added the HELPDESK group to give them:

- Create,delete, and manage user accounts
- Reset user passwords and force password change at next logon
- Modify the membership of a group

That let the HELPDESK group create users, delete them and reset passwords which is what I wanted, but they couldn't join accounting users to the ACCTGUSERS group.  So, I went to the Accounting OU/Groups OU, right-clicked it to delegate control and chose:

- Modify the membership of a group

That allowed me to accomplish what I needed.  However, now the HELPDESK group can go into the ACCTGUSERS group and add ANYONE they want, including domain admins and user accounts from OUs that they should not be able to edit.

Is there a way to allow the HELPDESK sec group to only let users in the Accounting OU be added to the ACCTGUSERS group?

Running 2008 R2 forest/domain levels.

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 6 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 6 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros