Solved

how to assign user account only enable and disable user function at AD ?

Posted on 2014-02-04
5
324 Views
Last Modified: 2014-02-22
I only grant a enable/disable account function to special AD account. how to do that ?
0
Comment
Question by:jimlo1
  • 3
  • 2
5 Comments
 
LVL 6

Expert Comment

by:Biniek
ID: 39834910
You have to delegate special permissions " Read userAccountControl and Write userAccountControl" for user accounts.

There are some instructions how to do it:

http://www.jasonprahl.com/2006/06/delegate-control-to-disableenable-user-accounts/

http://thebackroomtech.com/2009/07/01/howto-delegate-the-enabledisable-accounts-permission-in-active-directory/
0
 

Author Comment

by:jimlo1
ID: 39841166
Hi Biniek,

I implemened your instrustion but it doesn't work as attached
result.docx
0
 
LVL 6

Accepted Solution

by:
Biniek earned 500 total points
ID: 39841435
Hi Jimlo1,

In Your question You asked about enable/disable account, and now You want to Unlock user account,

id does not work, because there was other permissions

There is information how to delegate the Unlock Account Right:

How can I delegate the right to unlock locked Active Directory (AD) user accounts?
http://windowsitpro.com/security/q-how-can-i-delegate-right-unlock-locked-active-directory-ad-user-accounts
0
 

Author Comment

by:jimlo1
ID: 39849295
Dear Biniek,

I followed your instruction. It is working . Thank you very much. But I found a other weird event in AD. I clicked a that checkbox in attached file and click "Apply" button. At a moment, this checkbox is unclick . Why???????????
Checkbox-.docx
0
 

Author Comment

by:jimlo1
ID: 39863919
Hi Biniek or experts,

Can you help to solve this problem ?
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question