Solved

setup delegation in Windows 2012 R2 active directory

Posted on 2016-07-28
1
67 Views
Last Modified: 2016-07-29
Hello Experts,

To reduce Domain Admin count we need to be able to give the non-Domain Admins ability to:

Mange DNS
Manage GPO
Manage Server Object
Manage Service Accounts
Manage User Objects

can you please provide instructions step by step to setup delegation for a group of users and/or individual users in AD to perform tasks above?
0
Comment
Question by:Jerry Seinfield
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 40

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 41733518
DNS delegation is done in DNS management. You just Right Click the Server name in there, go to security, then set the permissions you want.

The same can be done in AD Users and Computers, but you have to have Advanced View enabled (Open ADUC, go to View, click Advanced Features). When that is enabled, you can right click the Domain or OUs you want to delegate, then go to properties, then click on the security tab. There are a lot of different types of access that can be granted, but you'll want to look for permissions related to Computer objects and User objects in the permissions list. You can also use the delegate access wizard in ADUC, but that has some limitations. Using the security tab is more granular. Note, also, that AD sees no difference between Servers and normal Computers from a permissions perspective. If you want them to have different permissions for Server objects and Computer objects, you will have to segregate them into different OUs, and delegate the permissions to the OUs individually.

GPO permissions are done in the Group Policy Management console. Click on an OU or the domain, then go to the Delegation tab. It will allow you to assign specific permissions (link GPOs, perform modelling analysis, etc) from there. You can grant permission to create GPOs by clicking on the Group Policy Objects folder, then selecting the Delegation tab. You'll have to delegate authority on existing GPOs by clicking the GPO, then going to the Delegation tab. This can only be done on a GPO by GPO basis. New GPOs will need to have permissions assigned as well.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question