Re: Delegating Administration to a user.

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,

Right Click -> Properties -> Security --> Advanced Tab of that
particular OU and check any "Deny" Type ACE is present for that user.

Adam,
ADManager Plus Team.

On Feb 20, 3:55 am, "Joe Richards [MVP]" <humorexpr...@xxxxxxxxxxx>
wrote:
Get and paste the text of a dsacls dump so we can see the actual delegation.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Editionwww.joeware.net

---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm

Michael wrote:
I have a user that I want to delegate the ability to create/delete users in
his OU, disable his accounts, and unlock user accouonts.

I did the delegate wizard in users and computers and the user can create the
account but cannot unlock a locked account. placed a check box in all
objects under delegate the following common tasks:

I also went under crate a custom task to delegate and gave full control to
all objects and this still had no effect.

Any suggestions would be greatly appreciated.

Thanks


.



Relevant Pages

  • Re: User Creation template terminal services profile DSADD
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... When creating a "template" user account all references to %username% are directly replaced with the template name. ... When trying the DSADD to create the accounts, DSADD does not seem to support the terminal services profile properties. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to prohibit an interactive logon and authorize an Ldap access
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... place of ADS_UF_NORMAL_ACCOUNT when creating the account. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Field greyed out when account ops try to unlock account
    ... Look at the permissions on the problem account with dsacls, ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: Reset password on krbtgt account?
    ... the account should be disabled. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.security)
  • Re: Unlock acct permissions
    ... It may actually be the best of the bunch but it is very old now so it is mostly about those GOOD FUNDAMENTALS that one needs and which Joe referenced. ... >>>Overall you appear to be a very "green" admin and you should buy one or more>>>books and learn this stuff before you do too much more. ... >>>Joe Richards Microsoft MVP Windows Server Directory Services ... How do I get DSACLS to run on a specific account? ...
    (microsoft.public.win2000.active_directory)