Solved

admin user that can only see their OU

Posted on 2013-05-16
3
452 Views
Last Modified: 2013-05-29
Hi

I was wondering if anybody could help,

We currently have a Mutli-Tenanted excahnge and Sharepoint that is working very good, recently we have been offering virtual desktops,

The question I have is our ad is setup which each customer having it's Own OU, and we have restricted access by gpo to not allow the users to do active directory lookups

We have been requested for admin access to these desktops and I have created GPO's and secuirty measures to ensure they can not see each others computers or services but the last part is the AD

I appricate that the AD is a Directory by nature and was designed to be one thus it makes sense that you can lookup every user and group

I can block AD lookup's altoghter but this restricts the admins from working on their own OU's having to manually type exact usernames

Is there anyway to set it up so that they can only see the users/groups and resources in there OU only

any help would be much appricated
0
Comment
Question by:CloudNut
3 Comments
 

Author Comment

by:CloudNut
Comment Utility
Forgot to mention it is on windows 2008 r2
0
 
LVL 78

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
Comment Utility
Create a restricted user that has admin options in their respective OU
http://technet.microsoft.com/en-us/library/cc778807(v=ws.10).aspx
0
 
LVL 36

Expert Comment

by:Jian An Lim
Comment Utility
what you are looking for is multi-tenant active directory.

http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/66d0f0ad-5e76-407d-b383-f8bce07930b3/

there is too many unstructured information so you need to find out what exactly can be achieve.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Join & Write a Comment

Suggested Solutions

Synchronize a new Active Directory domain with an existing Office 365 tenant
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now