Create OU but not users


i need give permission create ou's not users on domain. restricted group need create ou, delete ou, manage users, manage groups shouldn't able create or delete users.

hi,

yes, can use delegate control achieve this.

in aduc, right click container want permit users create ous , right click, open delegation of control wizard , add users or group want grant permission -> next , select "create custom task delegate" -> next -> select "only following objects in folder" , check "organizational unit objects", "create selected objects in folder" , "delete selected objects in folder" box -> next -> assign permission wanted -> next -> finish.

regards,
cicely





Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS