Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 58
  • Last Modified:

giving access to active directory to a manager


I want to give access to a manager to our active directory .... to only one group of users... so that he can unlock the accounts when they get locked out.

is there any plugin or software i can use for this purpose.

the manager is at our remote site location. Our environment is Windows server 2008 and Exchange Server 2010.

1 Solution
Dan McFaddenSystems EngineerCommented:
Here is link that describes "Delegating Control" of objects in AD.

Link:  http://support.microsoft.com/kb/294952

The article says to right-click on the domain, but you can also delegate down at the OU level.  So if all you users are under a specific OU, I would do this from there.  This way the person or group can only unlock accounts the are children of the location.  The delegate control wizard will walk you thru assigning the permission(s) you want to give out.

VB ITSSpecialist ConsultantCommented:
No plugin or software needed, you can do this via ADSI Edit. See here for the steps: http://support2.microsoft.com/default.aspx?scid=kb;EN-US;279723
o0JoeCool0oAuthor Commented:
is there any app so that the manager can use on his phone to unlock accounts?
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Dan McFaddenSystems EngineerCommented:
None that I know of.
Neil RussellTechnical Development LeadCommented:
AD HelpDesk Lite by IMPLBits.com for IOS devices
Joshua GrantomSenior EngineerCommented:
yep Neil is right, I used AD Helpdesk for a long time. You do need a VPN connection or have wireless access to the lan when on site.

Featured Post

Free recovery tool for Microsoft Active Directory

Veeam Explorer for Microsoft Active Directory provides fast and reliable object-level recovery for Active Directory from a single-pass, agentless backup or storage snapshot — without the need to restore an entire virtual machine or use third-party tools.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now