Solved

limit AD Helpdesk account

Posted on 2014-03-31
1
546 Views
Last Modified: 2014-04-04
Hi,

I need to create a Active Directory user account that has the ability to join a pc to the domain, create user accounts and Exchange 2010 mailboxes.

What groups would the user need to be a part of?

We do not want the user to have full domain admin, or server admin. The account is for a helpdesk tech.

Thanks!
0
Comment
Question by:Encinitas
1 Comment
 
LVL 35

Accepted Solution

by:
Mahesh earned 75 total points
ID: 39967785
In default domain Policy grant account "add workstation to domain" user rights

Finally use delegation of control wizard at domain.com level and give delegated permission to that account to join computers to domain

The above two permissions are required in order to work that properly

Also Add user to accounts operator built-in group in active directory for user management
This includes password reset, new account creation, adding and removing from groups, changing common attributes such as phone no and so on.

Assign that account recipient management role on exchange server to manage mailboxes

Mahesh.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

A procedure for exporting installed hotfix details of remote computers using powershell
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now