Solved

Restricted User Administrator

Posted on 2013-11-04
1
318 Views
Last Modified: 2013-11-06
We would like to create a security group for a set of users to have restricted user administration privileges.

Right now we have it so that (pretty much like default) Win 7 users can go to 'Network Locations' from 'My Computer' and click the 'Search Active Directory' tab. From there they can find their account and modify only their first 2 tabs of information.

We would like to make a security group where members of that group can search for any user and modify those first two tabs of information (and one of the 3rd). This would allow us to bypass installing  RSAT / ADUC for each of the members of that security group.

I have not been able to find an accurate listing of which permissions would allow this as we want to only allow the minimum amount of extra changes.

Here is a specific list of the fields we want the users to be able to modify:

General Tab - First Name, Last Name, Display Name, Telephone, Email, Home Page
Address Tab - Street, PO Box, City, Zip/Postal Code, Country/region
Business Tab - Office

Any help would be greatly appreciated! As this is for a number of users I want to make sure we implement only the proper permissions and don't end up with issues down the line.

Thanks!!!
0
Comment
Question by:PDGPA
1 Comment
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 39622552
You can give that group permissions to specific attributes.  The screenshot below is from the delegation control wizard (custom task).  You can also modify the ACL

Delegate
Thanks

Mike
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question