• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 372
  • Last Modified:

How do I provide limited Active Directory access so that a Helpdesk tech can utilize it to perform basic functions?

I have a Helpdesk tech that I would like to offload basic SysAdmin duties to. I would like to provide him access to Active Directory to do the simple functions like resetting Windows account, unlocking accounts, and changing password, etc. How do I configure AD for him so that he can perform only these functions? I do not want to give more access than that.

Environment: AD on Windows Server 2008 R2 Enterprise
1 Solution
Jeremy WeisingerSenior Network Consultant / EngineerCommented:
The Delegation of Control wizard should do the trick for you:
Cliff GaliherCommented:
This is a built in feature of Active Directory and is known as authority delegation. A good starting document is here:


Technet has a best practices guide and several more write-ups as well.
Zephyr ICTCloud ArchitectCommented:
Yes, like Jeremy mentioned, the delegation wizard will help you out nicely.

There's a nice how-to to be found here: http://kpytko.pl/2012/05/16/active-directory-rights-delegation-overview/
Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

Pradeep VIshwakarmaCommented:
However, always delegate rights to groups instead of individual users. Create a dedicated security group just for this particular rights delegation. It is much easier to manage those delegated rights by add/removing group membership than having to go back into the wizard or the security screen when you need make a change down the road.

Using a group makes the change more visible. No one would know a change has been made unless you go digging or have excellent documentation when making individual right changes to objects.


    Right Click on the OU that contains those users whose passwords you want to be reset
    Delegate Control
    Select the group/user you want to delegate rights to, Next.
    Select Create a custom task to delegate, Next.
    Select 'Only the following objects in the folder'
    Select 'User objects', Next.
    Unselect general
    Select property-specific
    Select read lockout time
    Select write lockout time
    Next, Finish.
Will SzymkowskiSenior Solution ArchitectCommented:
Typically when providing delegated access to groups I would personally create a new OU called Delegation Task (or something meaningful) and put all of the groups in the OU. From there you can then restrict access to this OU so that modifications cannot be done by anyone without access.

Security groups should also have meaningful names as well some examples would be

AD_USER_MOD (group to modify AD User attributes)
AD_COMP_MOD (group to modify AD Computer attributes)
AD_PASS_RESET (group to reset passwords for user account)

This is totally optional and I just wanted to provide some insight that having a meaningful displayname is much nicer than filling out the "description", althought still a good practice to do both.

SandeshdubeySenior Server EngineerCommented:
In addition you can also refer below KB link.

How to Delegate Basic Server Administration To Junior Administrators  http://support.microsoft.com/kb/555986
The good way to do this is by creating an OU structure so that you can delegate permissions and GPOs separately to different objects of AD. Please check this link for more info.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now