RE: mmc

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Numpty (Numpty_at_discussions.microsoft.com)
Date: 01/06/05


Date: Wed, 5 Jan 2005 21:11:01 -0800

Have you "delegated control" to the OU that he can reset passwords on?

If you do this he can ONLY reset passwords and nothing else unless you
specify it.

As he gets more savvy you can rerun the delegate control wizard and add
rights he is signed off on.

To my knowledge you can't disable right click, but if he hasn't got
permission to do the tasks listed on the right click then he won't be able to
(not sure if it is shown or not.)

If you only want him to be able to see that OU in the mmc, then select the
OU and go to the Action Menu > New Window From Here.

Minimise the windows in the MMC and close the full AD Console and save the
Console as a new MMC. This way he can't simply minimise and view everything.
You will want to do this in author mode, and if you want it so he can't stuff
about, change the MMC to run in User Mode, Limited Access, Single Window

Hope this helps.

There may also be a Group policy setting for the right click question but
I'm pretty sure it doesn't exist.

"peter" wrote:

> I have just tried creating an mmc for our trainee. We have server 2003 and
> 2000/xp clients. He is using XP.
>
> I would like the trainee to reset passwords only. But every time I create
> the mmc, the right click is still enabled so he sees everything. Can you
> disable the right click, if so how?
>
> Thanks
>
>



Relevant Pages

  • Re: Delegate Control to User
    ... Is the computer joined to the domain but the user just logging in locally? ... If that is the case I suppose to could run the MMC using the Run As... ... and delegated control to just reset passwords. ... only logged into Windows 2000 Pro locally. ...
    (microsoft.public.exchange2000.admin)
  • AD users and computers MMC to run from Windows XP
    ... I have delegated control of an OU, and want to create an MMC for the ... I created an MMC on the domain controller that just showed the OU the user ... Do I need to install the Windows Server 2003 administration tools onto the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegate Control to User
    ... You need to join that workstation to the domain so that it becomes "domain ... > The computer is not joined to a domain, just logging in locally. ... >> and delegated control to just reset passwords. ...
    (microsoft.public.exchange2000.admin)
  • Problems with assigning permissions
    ... Some of the administrators are not able to reset passwords of users. ... I have delegated control of the OU to these users yet it still tells them that they do not have permission. ... Any reasons why they would not be able to do this? ...
    (microsoft.public.windows.server.active_directory)
  • Problem with Custom MMC
    ... department to unlock users within his department without calling the ... I have delegated control to a group containing the user on the relevant OU, ... created the MMC with User - Full Access console permissions and also given ...
    (microsoft.public.windows.server.active_directory)