Link to home
Start Free TrialLog in
Avatar of rookie_b
rookie_bFlag for United Kingdom of Great Britain and Northern Ireland

asked on

2008R2 Active Directory - Delegate rights to users to join machines to AD but not users

Hello,

We have departmental technicians that need to be able to pre-stage and  join machines in particular OUs but not be able to create users. At the moment we just make them members account operators, but this gives them access to create both users and machines, and in any OU. Maybe if we could create separate groups that are similar to the Account Operators, but can only create/join machines to designated OUs? Or by using delegated rights, but really not sure what boxes to tick on that one.

Cheers!
ASKER CERTIFIED SOLUTION
Avatar of becraig
becraig
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of rookie_b

ASKER

Thanks for this, it looks like it is more or less what we need. Would this allow the members of that group to pre-stage computer accounts in that OU?
Yes once you grant the group permissions they will be able to perform any and all actions you grant the SG on that OU.