Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 594
  • Last Modified:

limit AD Helpdesk account

Hi,

I need to create a Active Directory user account that has the ability to join a pc to the domain, create user accounts and Exchange 2010 mailboxes.

What groups would the user need to be a part of?

We do not want the user to have full domain admin, or server admin. The account is for a helpdesk tech.

Thanks!
0
Encinitas
Asked:
Encinitas
1 Solution
 
MaheshArchitectCommented:
In default domain Policy grant account "add workstation to domain" user rights

Finally use delegation of control wizard at domain.com level and give delegated permission to that account to join computers to domain

The above two permissions are required in order to work that properly

Also Add user to accounts operator built-in group in active directory for user management
This includes password reset, new account creation, adding and removing from groups, changing common attributes such as phone no and so on.

Assign that account recipient management role on exchange server to manage mailboxes

Mahesh.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now