Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Delegation through AD

Posted on 2013-10-28
3
Medium Priority
?
229 Views
Last Modified: 2013-11-14
Good morning I have been successful with deploying delegation through AD on an OU. In fact I have been successful with applying delegation options to an OU through a security group.

Here is the problem I am having. I need to delegate for an additional 30 other OU's. How can I go through the process of selecting what I would like to delegate as far as permissions and then be able to apply this to other people on different sub ou levels. We are using server 2008 R2 sp1.
0
Comment
Question by:techdrive
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39605399
No easy way to forklift ACLs from one OU to another, would be a nice feature.  In theory you could script it out to check an OU and then apply the same permissions to another OU...I personally don't have that script written.

Delegation can flow to child OUs but it sounds like you want to copy the ACLs do other OUs too.

Thanks


Mike
0
 
LVL 10

Expert Comment

by:jmanishbabu
ID: 39605575
Use this software one of the best tools for delegation

http://www.quest.com/activeroles-server/
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 2000 total points
ID: 39605587
Your based bet would be to do this manually as you can take your time and ensure that you are delegating the permissions properly with no error.

You can in fact do this from powershell, but I would highly recommend that you test the script several times on different Test OU structures or even a totally isolated AD environment in a lab.

Below is a link to a great example to accomplish this in Powershell with entire break down. If you are not comfortable with powershell i would recommend doing this manually through the GUI.

http://blogs.technet.com/b/joec/archive/2013/04/25/active-directory-delegation-via-powershell.aspx

Will.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question