Re: Delegation issue



<tornado579@xxxxxxxxx> wrote in message
news:1158893323.542531.237330@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi group,

I am looking to delegate few of the activities like resetting passwords
and unlocking the accounts etc to the helpdek folks. I guess this can
be done with delegation wizard.

Sure, or even by making them Account Operators for the entire
domain (well, almost*).

But at the same time i want to ensure that they dont have the rights to
change the folder/files permissions and shutdown the server system. Is
there any way i can possibly acheive this ?

*Account Operators can actually logon to servers and (IIRC) shut
them down (not sure about the latter), but in generally granting specific
rights or permissions IS NOT going to let anyone change the permissions
on NTFS objects.

This latter is not quite true due to some bugs/features where if you
are an admin (or have enough power to install device drivers for
instance) there are ways around security.

Any inputs will be of great help.

Delegation wizard will do what you want probably. After that
you must use specific object permissions (rather than the simple
convenience of the permissions.)


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]

Thanks,
John



.



Relevant Pages

  • Re: Custom rights
    ... Try giving user who is adding account View Only Exchange Administrator ... >> To add computers to the domain go to AD Users and Computers. ... you will have to manually configure permissions on that user object ... >>> Look into AD delegation, though you may need to do some custom ...
    (microsoft.public.win2000.security)
  • Re: Assigning permissions throughtout AD for the security departme
    ... Thanks for the reminder about the delegation wizard. ... of the AD container you want to delegate permissions to - which, ... -Disable an account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Permissions to query Active Directory
    ... delegation of permissions. ... your admins might have delegated the permissions such ... Service (which uses the computer account when accessing the network), ... adequate permissions so it can query active directory for ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
    (microsoft.public.sharepoint.windowsservices)