Re: Delegating authority!
- From: JsX <JsX@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 14 Apr 2005 06:13:04 -0700
Herb - thanks for the reply -
I am aware of the delegation authority onto OU structure etc. but my
question is how to delegate authority to apply GPO onto Site to an account in
child domain??
I know there is some way to delegate it through sites & services "net
Services" node.
thanks
-Jim
"Herb Martin" wrote:
> "JsX" <JsX@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:18E26E09-FEA4-4A41-B030-AA851A4EC4FA@xxxxxxxxxxxxxxxx
> > Hi all -
> > Is there a way that an "enterprise Admin" can delegate permission to an
> > account in child domain to apply group policy on the child domain related
> > sites???
>
> Groups Policies are LINKED to OUs (not accounts)
> and that ability can be delegated.
>
> I cannot remember if this one is in the Delegation of
> Control Wizard but you can certainly do it direct with
> the OU object properties, Security (requires AD Users/Computers
> Advanced view)
>
> Also Full Control of the OU in question would accomplish this.
>
> > I know there is some way to do it through AD site & srv (service
> > node), but I am not quite sure how.
>
> Link Group Policy (on the OU)
>
> GPOs are then APPLIED to Users or Computers based on
> permissions (User or Computer must have BOTH "Read"
> and "Apply Group Policy" for it to work.)
>
>
>
.
- Follow-Ups:
- Re: Delegating authority!
- From: Herb Martin
- Re: Delegating authority!
- References:
- Delegating authority!
- From: JsX
- Re: Delegating authority!
- From: Herb Martin
- Delegating authority!
- Prev by Date: Re: trying to uninstall AD from a 2003 Machine
- Next by Date: Re: IntraSite or InterSite Replication.
- Previous by thread: Re: Delegating authority!
- Next by thread: Re: Delegating authority!
- Index(es):
Relevant Pages
|