Re: AD Delagation



Lorenz wrote:
I have to delegate to the helpdesk support the right to enable or disable an account in AD. ONLY enable/disable! I want to give them the minimum administrative right.

On what "Property-specific" of user object have to give the read/write access?

http://www.misguys.com/?p=150

As account disable\enable is handled through userAccountControll attribute You can't delegate right only for this specific operation as it is controlled by one of the bits in this value
http://support.microsoft.com/?id=305144

--
Tomasz Onyszko
http://www.w2k.pl/ - (PL)
http://blogs.dirteam.com/blogs/tomek/ - (EN)
.



Relevant Pages

  • Re: Active Directory Connector and exchange 5.5 question?
    ... and SC along with us are in the Forest and the only ... > that is using the same primary account. ... > defined via attributes on a user object. ... > because you would be trying to map more than one 5.5 primary windows nt ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Connector and exchange 5.5 question?
    ... The Wizard is seeing your 5.5 directory not your AD. ... the resource mailboxes. ... >> that is using the same primary account. ... >> defined via attributes on a user object. ...
    (microsoft.public.windows.server.active_directory)
  • Re: adding sIDHistory to an AD account
    ... the user object from AD, remigrate the user, reconnect the mailbox to the new ... > If I run ADMT2 and migrate the account to AD again can I run ADClean to merge the accounts? ... Basically you can't just insert whatever SID you want in. ... Using the GUI I add the sid in HEX and click OK. ...
    (microsoft.public.win2000.active_directory)
  • Re: Exchange Migration - Delegate Issues
    ... as it turns out is a disabled user object That would ... > Yes the same account as the workstation logon has mailbox rights. ...
    (microsoft.public.exchange.setup)
  • Re: Active Directory Connector and exchange 5.5 question?
    ... that is using the same primary account. ... defined via attributes on a user object. ... need to map a 5.5 user to a user object. ... because you would be trying to map more than one 5.5 primary windows nt ...
    (microsoft.public.windows.server.active_directory)