RE: Delegation of control wizard question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



You need to delegate a customize control to change user properties:

Delegating Control of Custom Tasks
The previous examples detailed varying levels of delegating control on
specific Active Directory containers. For the delegation of specific tasks,
predefined options were selected for delegation. The Delegation of Control
Wizard provides an additional level of granularity allowing for custom-built
tasks to be assigned to specific users or groups. In the following section,
the HRTeam will be assigned permissions to modify specific user attributes to
facilitate general employment operations.

To assign control for creating and deleting a user’s personal information in
Active Directory to the HRTeam

1.
In the left pane, right-click Divisions OU, and then click Delegate
control. The Delegation of Control wizard appears. Click Next.

2.
On the Users or Groups page, click Add, click Advanced, and then click Find
Now. Scroll to HRTeam, double-click HRTeam, and then click OK. Click Next to
continue.

3.
On the Tasks to Delegate page, click Create a custom task to delegate.
(This allows you to delegate control of the entire container.) Click Next.

4.
On the Active Directory Object Type screen, click Only the following
objects in the folder.

5.
Scroll down to the final entry and select the User Objects check box. At
the bottom of the Active Directory Object Type screen, select both Create /
Delete selected objects in this folder check boxes. Review your settings as
shown in Figure 6, and then click Next to continue.



Figure 6. Creating a Custom Delegation


6.
On the Permission page, ensure that General is selected (default). Scroll
down and select the Read and write personal information check box as shown in
Figure 7.

Note: Selecting the property-specific check box will provide an additional
level of detail at the attribute level. For example, if you only wanted the
HRTeam to be able to change a user’s street address, you would select that
particular attribute.



Figure 7. Creating a Custom Delegation, Assigning Specific Rights


7.
Click Next to continue.

8.
On the summary page, review the proposed settings, and then click Finish.

Hope this will help.

Regards,

Ashish

http://yashcare.blogspot.com

"Zack" wrote:

We are running Windows 2003 as our domain controllers. I'm using
"Delegation of control wizard" to give our helpdesk the required permissions
to change users' smtp addresses in the properties of the user in Active
directory (Active Directory Users and Computers > Select User > Right Click
> Properties > Email Addresses > New..."
What object type should I choose to give that right?



.



Relevant Pages

  • Re: join domain/create computer accounts... driving me NUTS!
    ... i added the following text to template6 and it doesnt even show up ... when i go to delegate control at the domain level!!!! ... "Account Restrictions" ... have you ever read the delegation of control white ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegation of rights
    ... > side the OU you have delegated the control to, ... Delegate only the required rights, in this case may not full ... May only to child objects within the OU and so on. ... >>> May the Step-by-Step Guide to Using the Delegation of Control Wizard can ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegation of rights
    ... side the OU you have delegated the control to, ... Delegate only the required rights, in this case may not full ... May only to child objects within the OU and so on. ... >> May the Step-by-Step Guide to Using the Delegation of Control Wizard can ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegate Control?
    ... For delegation of control check: ... Do "normal" users have access to query AD OU's? ... Why would an account that has no other rights be ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegation Rights
    ... Reset user passwords is a common task OR you can select custom task/only the ... For computers see method two in the ... > delegation tasks that are custom. ...
    (microsoft.public.win2000.security)