Solved

I need to set up a user in active directory to modify cosmetic account settings, such as office, address and display name, what group can I put it in?

Posted on 2014-02-25
3
290 Views
Last Modified: 2014-02-26
We have a 2008r2 active directory domain. I need to set up a user so she can use ADUC (active directory users and computers) to modify cosmetic changes in user accounts, such as job title, address and display name. I have tried making her an acccount operator but that does not give her permission to change anything. Is there a group other then domain admin, that I can use?
0
Comment
Question by:Thor2923
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 39885825
You can use the delegation control wizard > custom task > user objects and then give rights to spefic properties.

I'm at work so can't transfer screenshots right now but I can later if you would like...just let me know.

Thanks

Mike
0
 
LVL 4

Expert Comment

by:michaelalphi
ID: 39888095
Hi Thor,
You can follow step-wise instruction explained in this article to modify cosmetic changes in user accounts : http://www.activewin.com/win2000/step_by_step/active_directory/delegsteps.shtml
Hope, this helps you.
0
 
LVL 1

Author Closing Comment

by:Thor2923
ID: 39889791
worked like a champ! thanks
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question