Delegate permission to set primary group


hi all,

we have created universal group providing vpn access external users. purpose need set universal group primary group , remove user accounts "domain users" group.

our helpdesk team responsible creating users accounts, not have permissions set primary group.

i tried assigning "write primarygroup token" helpdesk group, didn't work.

what permissions required delegate permission group or user?

 

thanks

 


thanks vishnu r

hi,

i not suggest place helpdesk stuff "account operators" group. grant them more rights need. security reasons not that.

instead of primarygroup token did try allow write primary-group-id ?
http://msdn.microsoft.com/en-us/library/windows/desktop/ms679375(v=vs.85).aspx


regards, krzysztof ---- visit blog @ http://kpytko.wordpress.com


Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com