Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

AD Delegate Control

Posted on 2013-01-21
3
Medium Priority
?
309 Views
Last Modified: 2013-01-23
Hi Experts,

I would like to delegate some admin rights to a user.
I want the user to be able to fully administer user accounts, some OUs, join PCs to the domain but nothing else. How can i do this?

Thanks

Rio
0
Comment
Question by:Rio_10
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 750 total points
ID: 38801037
You could use the builtin account operators group or delegate the rights using the delegation wizard  (or modify ACLs directly)

You can use group policy to let them add computers to the domain

Under Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment
 "Add workstations to domain"

Thanks

Mike
0
 
LVL 13

Accepted Solution

by:
imkottees earned 750 total points
ID: 38801128
0
 

Author Comment

by:Rio_10
ID: 38809305
This is great thanks.

I want to give a particular user RO access to DHCP. I have added the user to DHCP users group but i want the user to use RSAT and not login to the DHCP server directly.
when the user opens the DHCP console via RSAT I get an error that the DHCP service is not running on the target computer.

any ideas?
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question