Solved

Restricted User Administrator

Posted on 2013-11-04
1
317 Views
Last Modified: 2013-11-06
We would like to create a security group for a set of users to have restricted user administration privileges.

Right now we have it so that (pretty much like default) Win 7 users can go to 'Network Locations' from 'My Computer' and click the 'Search Active Directory' tab. From there they can find their account and modify only their first 2 tabs of information.

We would like to make a security group where members of that group can search for any user and modify those first two tabs of information (and one of the 3rd). This would allow us to bypass installing  RSAT / ADUC for each of the members of that security group.

I have not been able to find an accurate listing of which permissions would allow this as we want to only allow the minimum amount of extra changes.

Here is a specific list of the fields we want the users to be able to modify:

General Tab - First Name, Last Name, Display Name, Telephone, Email, Home Page
Address Tab - Street, PO Box, City, Zip/Postal Code, Country/region
Business Tab - Office

Any help would be greatly appreciated! As this is for a number of users I want to make sure we implement only the proper permissions and don't end up with issues down the line.

Thanks!!!
0
Comment
Question by:PDGPA
1 Comment
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 39622552
You can give that group permissions to specific attributes.  The screenshot below is from the delegation control wizard (custom task).  You can also modify the ACL

Delegate
Thanks

Mike
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
An article on effective troubleshooting
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question