Re: Permission to deny moving of OU objects
- From: "Anthony" <anthony.spam@xxxxxxxxxxxxxx>
- Date: Wed, 19 Sep 2007 18:41:02 +0100
You'd have to make it so that admins of OU1 have no right to create objects
in OU2. Then they can't move it there.
Accidentally moving a country OU seems like a big step, and I would be
restricting admin rights to people who know what they are doing,
Anthony,
http://www.airdesk.co.uk
"Dylan" <Dylan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:964CE946-8F63-42B2-8C15-8C0FB3F687F2@xxxxxxxxxxxxxxxx
Hi,
We have a single domain structure with multip OUs under Root domain to
separate sites in different location. For example:
company.com
|_CA
|_NV
|_AZ
|_CO
I've set Deny Delete of Organizational Unit to "This Object and all Child
Objects" for Root domain as well as site OUs for a particular group. Is
there a way to set permission so the same group cannot move the OU to
under
another OU? There have been accidents where one OU was moved under
another
OU and Deny Delete OU object doesn't prevent that from happening.
Any suggestions?
Thanks.
.
- Prev by Date: Kerberos not working across domains
- Next by Date: Re: help on login script
- Previous by thread: Kerberos not working across domains
- Next by thread: Re: Permission to deny moving of OU objects
- Index(es):
Relevant Pages
|