Solved

Grant a single user access to edit a Global Security group?

Posted on 2014-03-18
2
2,148 Views
Last Modified: 2014-03-19
Really easy question;

In AD, how can I grant a single user access to add/remove members a Global Security group? I have two groups that I want to allow him to edit.

Thanks
0
Comment
Question by:GCTTechs
2 Comments
 
LVL 12

Accepted Solution

by:
piattnd earned 500 total points
ID: 39938420
You'll need to allow them access to the group itself.  You can do it with a single user making them the "manager" of the group and checking the box that says managers can update the member list. (under the Managed By tab).

Additionally, you can explicitly give permissions to multiple users in the Security tab on the group object.  Add the user and give only the "Read Member Property" and "Write Member Property".  (Verbiage of the option may be slightly different depending on your domain level).
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39938444
Hi,

Create a OU move that user to new OU and run the control delegation wizard. Select "Modify the Membership of Group" permission.
  http://www.howtogeek.com/50166/using-the-delegation-of-control-wizard-to-assign-permissions-in-server-2008/
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A safe way to clean winsxs folder from your windows server 2008 R2 editions
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question