Solved

Delegation through AD

Posted on 2013-10-28
3
223 Views
Last Modified: 2013-11-14
Good morning I have been successful with deploying delegation through AD on an OU. In fact I have been successful with applying delegation options to an OU through a security group.

Here is the problem I am having. I need to delegate for an additional 30 other OU's. How can I go through the process of selecting what I would like to delegate as far as permissions and then be able to apply this to other people on different sub ou levels. We are using server 2008 R2 sp1.
0
Comment
Question by:techdrive
3 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39605399
No easy way to forklift ACLs from one OU to another, would be a nice feature.  In theory you could script it out to check an OU and then apply the same permissions to another OU...I personally don't have that script written.

Delegation can flow to child OUs but it sounds like you want to copy the ACLs do other OUs too.

Thanks


Mike
0
 
LVL 10

Expert Comment

by:jmanishbabu
ID: 39605575
Use this software one of the best tools for delegation

http://www.quest.com/activeroles-server/
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 500 total points
ID: 39605587
Your based bet would be to do this manually as you can take your time and ensure that you are delegating the permissions properly with no error.

You can in fact do this from powershell, but I would highly recommend that you test the script several times on different Test OU structures or even a totally isolated AD environment in a lab.

Below is a link to a great example to accomplish this in Powershell with entire break down. If you are not comfortable with powershell i would recommend doing this manually through the GUI.

http://blogs.technet.com/b/joec/archive/2013/04/25/active-directory-delegation-via-powershell.aspx

Will.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Mapping Drives using Group policy preferences Are you still using old scripts to map your network drives if so this article will show you how to get away for old scripts and move toward Group Policy Preference for mapping them. First things f…
Ever notice how you can't use a new drive in Windows without having Windows assigning a Disk Signature?  Ever have a signature collision problem (especially with Virtual Machines?)  This article is intended to help you understand what's going on and…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now