AD Delegation

Shawn
Shawn used Ask the Experts™
on
I want to Delegate Permissions to a Security Group in AD. Now I only want these permissions to be on certain OU's. Is there a way to quickly do this or automate it?

Right now I am manually doing each OU and it is just taking awhile.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooter

Commented:
Have you considered using powershell?  (Of course, like almost everything that involves scripting, it'll take a while and some effort to get the automation set up, but should be faster after that.)
To use the given below script:

$ou = "AD:\OU=Users,DC=contoso,DC=com"

$group = Get-ADGroup MyGroup
$sid = new-object System.Security.Principal.SecurityIdentifier $group.SID

$acl = get-acl $ou

$ace = new-object System.DirectoryServices.ActiveDirectoryAccessRule $sid,"GenericAll, ","Allow"

$acl.AddAccessRule($ace) set-acl -aclobject $acl $ou

and You can read this article for more information about this.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start Today