Re: Delegation of Control

From: Ulf B. Simon-Weidner [MVP] (nospam2-ulf_at_usw-consulting.com)
Date: 10/27/04


Date: Wed, 27 Oct 2004 19:39:51 +0000


"jv" <jv@discussions.microsoft.com> wrote in message
news:jv@discussions.microsoft.com:
> I just upgraded my test environment to w2k3 AD. Now I want to be able to
>
> delegate control for my helpdesk and desktop team to be able to reset
> passwords, unlock accounts, join computers to domain, remove computers
> from
> domain, and read access to view properties of accounts.
>
> What is best way to achieve this?

Hello jv,

The most tasks you outlined are in the delegation of control wizard,
just click on the approbiate OU and choose "delegation" from the
context menu.

Everybody has read access, so you don't need to configure that. And
they are able the change accounts they create. Reset passwords is
provided in the delegation wizard, create and delete computer objects
is provided.

To unlock locked user accounts you have to delegate write rights on the
"lockoutTime"-Attribute.

-- 
Gruesse - Sincerely,
Ulf B. Simon-Weidner
  MVP-Book "Windows XP - Die Expertentipps":  http://tinyurl.com/44zcz
  Weblog: http://msmvps.org/UlfBSimonWeidner
  WebSite: http://www.windowsserverfaq.org


Relevant Pages

  • Re: How does OU delegation work?
    ... If the account has full control of the OU, ... I'd expect them to be able to adjust user accounts, ... had a delegation of full control. ... Have you ever seen a hot blonde trying to admin an OU? ...
    (microsoft.public.windows.group_policy)
  • Help with proper delegation settings
    ... tool; Launching the Delegation Wizard; Created a Custom Task to Delegate; ... Only the following Objects and selected computer objects and checked off the ... The users can add accounts to the domain just fine; but we are in the midst ... so they can conform to the naming standards... ...
    (microsoft.public.windows.server.active_directory)
  • Re: OU Delegation & Security
    ... Delegate as follows in the Delegation of Control Wizard and it should allow ... delegates will have full control over users, computers, and groups in the OU ... > and then administer these accounts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Delegation Fails - Permissions Disappear
    ... in turn a member of the Print Operators group. ... inheriting permissions?? ... ACL on all security principals (users, groups, and machine accounts) present ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • OU Delegation & Security
    ... I'm trying to delegate control of users, ... This partly works - i.e. it allows the delegated user to create new accounts ... Shouldn't the delegation wizard give control to all objects within the OU to ... Any advice on how to remedy this would be much appreciated. ...
    (microsoft.public.windows.server.active_directory)