Pancake_Effect
asked on
User Control FOR Active Directory/Group Policy?
We have multiple IT admins hoping to work on the same active directory structure/group policy. Our servers are in a central location, but the facilities are separated geographically.
Is there a way we can separate it so IT admins from another facility cannot edit the settings for other places?
We have a newer facility, and want them to control only their objects and structure for only their items when they remote in.
So basically is there some type of "right" system within itself for active directory/group policy?
Is there a way we can separate it so IT admins from another facility cannot edit the settings for other places?
We have a newer facility, and want them to control only their objects and structure for only their items when they remote in.
So basically is there some type of "right" system within itself for active directory/group policy?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Exactly what I needed thanks!
Specifically step 5:
5. Delegate control of the OU—Start Active Directory Users and Computers. Right-click the desired OU and select Delegate Control. Add the group you created in step 4, and grant the group the appropriate rights for the OU.
Specifically step 5:
5. Delegate control of the OU—Start Active Directory Users and Computers. Right-click the desired OU and select Delegate Control. Add the group you created in step 4, and grant the group the appropriate rights for the OU.
Please specify bit clear.
Thanks