Re: Delegating authority!
- From: "Herb Martin" <news@xxxxxxxxxxxxxx>
- Date: Wed, 13 Apr 2005 17:13:09 -0500
"JsX" <JsX@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:18E26E09-FEA4-4A41-B030-AA851A4EC4FA@xxxxxxxxxxxxxxxx
> Hi all -
> Is there a way that an "enterprise Admin" can delegate permission to an
> account in child domain to apply group policy on the child domain related
> sites???
Groups Policies are LINKED to OUs (not accounts)
and that ability can be delegated.
I cannot remember if this one is in the Delegation of
Control Wizard but you can certainly do it direct with
the OU object properties, Security (requires AD Users/Computers
Advanced view)
Also Full Control of the OU in question would accomplish this.
> I know there is some way to do it through AD site & srv (service
> node), but I am not quite sure how.
Link Group Policy (on the OU)
GPOs are then APPLIED to Users or Computers based on
permissions (User or Computer must have BOTH "Read"
and "Apply Group Policy" for it to work.)
.
- Follow-Ups:
- Re: Delegating authority!
- From: JsX
- Re: Delegating authority!
- References:
- Delegating authority!
- From: JsX
- Delegating authority!
- Prev by Date: Re: Logon Scripts not executing when logging on client computers
- Next by Date: Re: HELP! KCC not running?
- Previous by thread: Delegating authority!
- Next by thread: Re: Delegating authority!
- Index(es):
Relevant Pages
|