RE: Assigning some rights to users

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Pat Cai[MSFT] (v-patcai_at_online.microsoft.com)
Date: 03/03/05


Date: Thu, 03 Mar 2005 07:27:11 GMT

Hi,

The address, telephone etc information belongs to the User object in AD. We
are unable to modify them in Outlook.

My understanding of your concern is: You want your clients to update their
own personal information those displayed in GAL. For this purpose, we have
a utility, GAL MOD to achieve it. User can modify his personal data,
including telephone, address, company etc by using this utility. For some
reasons, this utility has not been published yet, so please give me your
available email address and I will send it to you directly. My email
address is v-patcai@microsoft.com.

Note:

1. By default, an ordinary user only has the permission to modify his own
personal info, but not others.
2. This utility is provided with no warranties, you will take your own risk
if you choose to use it.

If you want to have someone (not the system admin) also be able to modify
other's information, you should delegate some AD permissions to him. To do
so:

1. Open "AD Users & Computers"
 
2. Right click the Users contained and select "Delegate Control"
 
3. Add the Group or User that you want to delegate this permission to the
List,

4. Select "Create a custom task to delegate"
Select "Only the following objects in the folder:
Select "USER OBJECTS"
 
5. Under Permissions we check "General", select "write Personal
Information" and then click OK
 
Note: Users having admin right rights cannot be changed by the delegated
users. For normal users, if you find that you cannot edit personal
information for any normal user, it is because this user object blocks
security inheritance. You can confirm it by the following steps:
 
1. Open ADU&C, click View, and select "Advanced Features"
 
2. Right click the user->properties->security. The Group you delegated is
not list.
 
3. Click Advanced, you should see "Allow inheritable permissions from the
parent to propagate to this object and all child objects." is not checked.
 
Therefore, the user object does hot inherit security settings when you
delegate the permissions. To work around the issue, you could manually add
permission to the user. Or, you could check "Allow inheritable permissions"
to the user and run delegate wizard again.

Hope the information helps.

Since it is an AD problem in nature, so if you still have questions
regarding this "delegate controls" process, I also suggest you post a new
thread in the following newsgroups, so that you can get more assistance
from those who mainly focus on AD.
 
Microsoft.public.win2000.active_directory

Hope the information helps.

Regards,

Pat Cai
Microsoft Online Partner Support

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
Business-Critical Phone Support (BCPS) provides you with technical phone
support at no charge during critical LAN outages or "business down"
situations. This benefit is available 24 hours a day, 7 days a week to all
Microsoft technology partners in the United States and Canada. This and
other support options are available here:

BCPS:
https://partner.microsoft.com/US/technicalsupport/supportoverview/40010469
Others: https://partner.microsoft.com/US/technicalsupport/supportoverview/

If you are outside the United States, please visit our International
Support page:
http://support.microsoft.com/default.aspx?scid=%2finternational.aspx.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: extend permissions in AD
    ... a custom task to delegate" option using the above wizard. ... would be nice if I can modify the ADSIEdit to show my customized ... >> Is there a way to extend the set of permissions in AD? ... edit directions, modify directions etc.? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password never expires
    ... To delegate you need at least: ... "Reset Password" extended right on the user object is needed AND you need ... Read/Write permissions on the attribute "pwdLastSet". ... The "password never expires" option is represented by a BIT/FLAG in the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Password never expires
    ... To delegate you need at least: ... "Reset Password" extended right on the user object is needed AND you need ... Read/Write permissions on the attribute "pwdLastSet". ... The "password never expires" option is represented by a BIT/FLAG in the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegate Control?
    ... > I would like to have one of our users have the permissions to modify the user properties such as ... OU and then delegate for this user control over this groups (via ... delegate wizard -> create custom task) without right to create or delete ...
    (microsoft.public.win2000.active_directory)
  • Re: Modify Telephone Number privilege
    ... is there a way to allow exchange users to update their ... How can I delegate each user rights to update their infomation ... followed by "User object" in the "Only the following objects in ... Telephone Number and Write Telephone Number permissions on the Permissions ...
    (microsoft.public.windows.server.active_directory)