RE: AD Delegation

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Dear Alex,

The issue is resolved by providing the acces " Delete Subtree" because it is
the access required to delete all the objects under that container. The
access have been given on Computer object only.

Thanks you all for your support

Sukhwinder

"Alex van Gemst - MCSE / MCITP EA" wrote:

Dear,

Go to the properties for the OU
Choose Advanced
Choose the group you want to delegate the permissions to
Click Edit...
Choose Apply onto: 'Computer Objects'
Select 'Allow Delete Printer Objects'
or 'Delete all Child Objects' if necessary

I think this should enable the local IT staff to delete those computer
accounts

Hope this helps you,

Alex van Gemst - MCSE / MCITP EA




"Sukhwinder Singh" wrote:

Dear All,

We are having a Single Domain structure with more than 10000 Computer
objects. We have created the Diffrent OU's for different Divisions in the
organisation and delegated the permissions to the local IT staff for the
Account management wherein they can create, modify and delet objects within
their divisional OU's.

We are facing the issue with some of the computer accounts which have got
printer or any other device attached to those. The local IT teams are not
able to delete these computer accounts as they are treated as container
objects.

If I give them access to delete container objects then they will be able to
delet the OU's also which is a security risk.

Is there any way to delegate the control to delete the computer accounts
without delegating permission to delete other container objects like OUs.
.



Relevant Pages

  • Re: Delegate "rename computer"
    ... When you use the delegation wizard for Join computers to the domain it gives the user rights to create a computer account and through CREATOR/OWNER permissions you will find that they can rename computer accounts they have created, but they wont be able to rename account created by other Admins because the delegations of control wizard doesn't grant them the "delete" right for computer accounts. ... In our multi-site enviroment we are trying to delegate some tasks to specific ...
    (microsoft.public.windows.server.active_directory)
  • RE: AD Delegation
    ... Choose the group you want to delegate the permissions to ... We are facing the issue with some of the computer accounts which have got ... If I give them access to delete container objects then they will be able to ... Is there any way to delegate the control to delete the computer accounts ...
    (microsoft.public.windows.server.active_directory)
  • Re: add workstations to domain
    ... Directory computers container can also create computer accounts in the ... The distinction is that users with permissions on the container are ... computer accounts that are created by means of "Add workstations to domain" ...
    (microsoft.public.win2000.security)
  • Re: Permissions for joining XP computers to domain
    ... They would need create computer objects permission for the domain or ... container where the computer accounts are being created. ... I want to give help desk people the permissions necessary to do this BUT ...
    (microsoft.public.windows.server.security)
  • Re: account for tech to add pcs to domain
    ... Which container did you delegate access for? ... add or delete computer accounts to or from a container. ... Problem is that I cant add computers to ...
    (microsoft.public.win2000.active_directory)