Re: IMPACT of (Delegation Control of Group Policy) on Active Direc



not clear!!

"Paul Bergson [MVP-DS]" wrote:

Inline

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Tariq Ziad" <TariqZiad@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:038969A1-C152-4E3F-94C7-6C59F0C35548@xxxxxxxxxxxxxxxx
Dear All,

I'd like to ask about the bad effects, impact on the health of active
directory that could result from delegating control of group policy
creation,
editing, linking on OU of Computers and Users OR on Site level to an
engineer
who is only responsible for desktops and laptops (SUPPORT Engineer). I
mean
he is responsible to every thing related to installing OS, Software, and
all
kind of OS and Software settings for users( i.e. on there computers). He
is
not responsible of dealing with any activity related to servers or Active
Directory.
Active Directory is totally managed by a system engineer responsible for
AD,
Exchange, and other print, share and application servers.

Would it harm to delegate control of group policy on OU of computers and
users or on sites to SUPPORT Engineer since his area of responsibility is
desktops and laptops?? Would that have any effect on Servers and AD?
I hope you lead me to Microsoft articles and documents related to this
IMPACT subject

No
..

A small example:
1) if there is an OU that have 10 computer accounts and this SUPPORT
Engineer has delegation of control to create group policies and link them
to
this OU, then how would this harm Active Directory and Domain Controllers.
Also, I mean would creating a GPO and having it appearing in the active
directory even without linking it to any container level (SITE, DOMAIN,
OU),
would that have any harm on the domain container containing it??

He could not impact any other object other than the objects within the ou in
which
he has delegated authority of. He can only maintain those object types for
which
he has been delegated authority over.



2) if there is a site that have computers and servers and this SUPPORT
Engineer has delegation of control to create group policies and link them
to
this Site, then how would this harm Active Directory, Domain Controllers,
and
Servers. How could servers be excluded from any group policy applied on
the
site level, i.e could block inheritance help if these servers are included
in
an OU?


Same thing he can only manipulate those objects within this ou. He can only
maintain those object types for which he has been delgated authority over.

Regards,
Tariq Ziad



.



Relevant Pages

  • Re: IMPACT of (Delegation Control of Group Policy) on Active Directory
    ... directory that could result from delegating control of group policy ... who is only responsible for desktops and laptops (SUPPORT Engineer). ... Exchange, and other print, share and application servers. ... Engineer has delegation of control to create group policies and link them ...
    (microsoft.public.windows.server.active_directory)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Direc
    ... GPOs applied on DCs and Servers ... Health of active Directory and DCs since unSYSTEM Engineer is having ... Actually my MAIN CONCERN is that how would delegating control of Group ... Policy to SUPPORT Engineer affect health of active directory?? ...
    (microsoft.public.windows.server.active_directory)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Direc
    ... I am the SUPPORT Engineer, and the SYSTEM Engineer is claiming that AD ... I was delegated control of GP on site ... only on windows 2000 and XP computers, but you know this way servers will be ...
    (microsoft.public.windows.server.active_directory)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Directory
    ... and that can be ANYTHING like client, servers and even DCs. ... I would not delegate ... directory that could result from delegating control of group policy ... who is only responsible for desktops and laptops (SUPPORT Engineer). ...
    (microsoft.public.windows.server.active_directory)
  • Re: dns administration delegation
    ... Allow site_DNSadmin group to FULL control Computer Configuration\Windows ... Executed dnsmgmt.msc and added one of the dns servers. ... additional permissions that grant unnecessary rights. ...
    (microsoft.public.windows.server.dns)