How to allow users to create groups and shares

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,

I started in a new company some time ago, and I'm now looking at the
policies etc. During this work I found that 10 users are member of the
administrators group in the domain. Now there's no way this is necessary so I
want to remove most of these users, but some of them will still need to be
able to administer a specific share on the file server. This includes
creating new shares within the existing share, and create groups and
maintaining membership of these groups to grant access for only certain users
to the shares within the existing share.

Now my question is how can I best limit their rights to only do this? I've
been thinking about adding the users to the Account Operators group, but this
will give them permission to create, modify, and delete accounts for users,
groups, and computers in all containers and organizational units of Active
Directory except the Builtin container and the Domain Controllers OU. If
possible I'd like them to only be able to create and administer groups and
not create users and computers. I don't think this group will allow them to
create shares either, but can I achieve this my adding them to the Power
Users group?

If I can't achieve my goal with any of the built-in groups can I then create
a new group and grant this one the necessary permissions?

Thanks in advance,
Ronnie
.



Relevant Pages

  • Re: Default Shares on Member Servers
    ... On the client, there are no persistent shares, and no stored credentials. ... On the member servers, the local Administrators group contains Domain\Domain ...
    (microsoft.public.windows.server.security)
  • Re: List users in local administrators group on remote machine
    ... list all users in local administrators group on ... remove user from local administrators group on remote computer ... ' Check first if they are already a direct member. ...
    (microsoft.public.windows.server.scripting)
  • Re: How to make a AD group member of the local administrators grou
    ... Can I use your script and replace the user ingo with the group info or do I ... Clemens de Brouwer ... that group to the local Administrators group. ... ' Check if user already a member. ...
    (microsoft.public.windows.server.scripting)
  • Re: How to allow users to create groups and shares
    ... They should be member "Power users" group on the server to create/manage shares on member servers. ... For DC's you can use "server operators", keep in mind this group has also high permissions on DC's: ... For the AD part, create a new security group and add the accounts that need the permissions, then use "Delegation of control wizard". ...
    (microsoft.public.windows.server.active_directory)
  • Re: Restricted Groups problem
    ... member servers in "sub.domain" via group policy. ... administrators group. ... Are you trying to add a global group to a global group? ... On member servers in the web servers OU of sub.domain, ...
    (microsoft.public.windows.server.active_directory)