Re: Delegation of groups admin. - restricted to a subset of objects



Actually you can add ANY AD object, doesn't have to be a security principal. Of course, anything other than a security principal isn't going to grant anything...

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Jorge de Almeida Pinto [MVP - DS] wrote:
the original poster states:

"only add a certain set of computers as members to a set of groups"

this is not possible!

why?

if you are delegated the right to manage group membership, you are delegated the right to make EVERY SECURITY PRINCIPAL (users,groups,computers) a member of that group

.



Relevant Pages

  • Re: Active Directory Permissions
    ... I would like to be able to grant certain members of the IT department ... using "active directory for users and computers". ... permissions. ...
    (microsoft.public.windows.group_policy)
  • Re: aduc or dsa.msc limitations
    ... Take the instance where you have 1000 members in a group, instead of a single LDAP query, it would require 1001 queries. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Counting Member in a Group
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ... I can get ADFIND to find out all the members in a group but then csvde gives me about 14,000 of groups so I think I will have problem in counting the number of members in a group one by one in ADFIND output. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Member OF
    ... Users and contacts aren't members of OUs. ... OU's and containers are simply to configure a hierarchy. ... You sound like you are talking about a group. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Add another domain user group to local administrators of all computers in an OU with removing ot
    ... If you have a group "mylocaladmins", which is added to restricted groups, with user1, user2 and user3 you can add or remove accounts to this group without effecting the other users in the group, they will still be local admins. ... But if you have so different needs with separating computers, you have to do a good planning before, what you will achive in for which users/groups. ... Select add on the Members of this group and then add the members ...
    (microsoft.public.windows.server.active_directory)

Loading