Solved

admin user that can only see their OU

Posted on 2013-05-16
3
458 Views
Last Modified: 2013-05-29
Hi

I was wondering if anybody could help,

We currently have a Mutli-Tenanted excahnge and Sharepoint that is working very good, recently we have been offering virtual desktops,

The question I have is our ad is setup which each customer having it's Own OU, and we have restricted access by gpo to not allow the users to do active directory lookups

We have been requested for admin access to these desktops and I have created GPO's and secuirty measures to ensure they can not see each others computers or services but the last part is the AD

I appricate that the AD is a Directory by nature and was designed to be one thus it makes sense that you can lookup every user and group

I can block AD lookup's altoghter but this restricts the admins from working on their own OU's having to manually type exact usernames

Is there anyway to set it up so that they can only see the users/groups and resources in there OU only

any help would be much appricated
0
Comment
Question by:CloudNut
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 

Author Comment

by:CloudNut
ID: 39172885
Forgot to mention it is on windows 2008 r2
0
 
LVL 82

Accepted Solution

by:
David Johnson, CD, MVP earned 250 total points
ID: 39173785
Create a restricted user that has admin options in their respective OU
http://technet.microsoft.com/en-us/library/cc778807(v=ws.10).aspx
0
 
LVL 37

Expert Comment

by:Jian An Lim
ID: 39173792
what you are looking for is multi-tenant active directory.

http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/66d0f0ad-5e76-407d-b383-f8bce07930b3/

there is too many unstructured information so you need to find out what exactly can be achieve.
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Here's a look at newsworthy articles and community happenings during the last month.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question