Solved

Delegate help desk To unlock AD Accounts:

Posted on 2014-01-13
12
1,505 Views
Last Modified: 2014-01-13
Delegate help desk To unlock AD Accounts:

I need to delegate Helpdesk to unlock AD account for users that have higher privileges than the Desktop users who have only Domain users privileges.

I believe this can be done through AD Delegation

Any step by step with screenshots will be vey much helpful.

Thanks
0
Comment
Question by:jskfan
  • 7
  • 4
12 Comments
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 100 total points
ID: 39777352
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 39777353
Yes you are correct. You can accomplish this using the delegation of Control Wizard.

The following link illustrates exactly how to do this providing screenshots.

Reset Password Delegation of Control Wizard.
http://community.spiceworks.com/how_to/show/1464-how-to-delegate-password-reset-permissions-for-your-it-staff

Will.
0
 

Author Comment

by:jskfan
ID: 39778051
when you apply the delegation at OU level, it should apply to only that OU...Correct?
but how do I verify that the Delegation was applied to only that OU...
and confirm that user group  I gave permissions to unlock account at OU1 is not able to do the same at OU2 level ?

Thanks
0
 

Author Comment

by:jskfan
ID: 39778054
I found out checking the security tab of an OU will show if the user group I gave permission is there or not... disregard my last comment....
0
 

Author Comment

by:jskfan
ID: 39778060
however if I open up properties of user group I gave permissions and click Advanced then select the group click Edit , next to Apply to : Descendant User objects.
it does not tell you to which OU is applied to ....
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 39778073
Not it does not. If you compare the OU's, that that has delegated control and another that does not you will see on the Advance>Security that the permissions are different.

If you apply the permissions to a top level OU all OU's underneath the will inherite the permission by default. You can however go into Advance Security and remove the Inheritance (not sure why you would want to) but you can.

The only way you can delegate permissions which will affect all top level OU's is applying the same Delegate of Control to the domain (i do not recommend this).

For testing when a user tries to modify AD object that are not in an OU where permission was delegated it will appear as if they can make the chagne but as soon as they try and apply the change it will give then an Access Denied error.


Will.
0
 

Author Comment

by:jskfan
ID: 39778121
But how do you audit the user group to which object has permissions?
when I go back to the user group  I created and gave it Delegation, I can not tell to which OU it has delegation....

Until , I go to the OU then I see the user group there under Security tab,
0
 
LVL 53

Accepted Solution

by:
Will Szymkowski earned 400 total points
ID: 39778156
In Active Directory there are no native tools to accomplish this. You will need to purchase 3rd party tools which will allow you to accomplish what your looking for. My personal advice is if you are not looking to purchase additonal software you can use the Description Field for the group and specify the OU's that it has been setup for delegation.

Some of the big providers for AD Tools would be Manage Engine and Quest Software (Dell).

Manage Engine AD Manager - http://www.manageengine.com/products/ad-manager/index.html?ADMPID=50006&kw=active+directory&adId=7780351362

Will.
0
 

Author Comment

by:jskfan
ID: 39778222
mmmm...

I realized the Delegated security group cannot unlock domain admins account..
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 400 total points
ID: 39778267
Not sure exactly what your askiing...

Will.
0
 

Author Comment

by:jskfan
ID: 39778282
http://windowsitpro.com/security/q-how-can-i-delegate-right-unlock-locked-active-directory-ad-user-accounts

followed steps 1 to 9
but I could not get a domain user to unlock account of a Domain Admins user
0
 

Author Closing Comment

by:jskfan
ID: 39778347
Thanks
0

Join & Write a Comment

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now