Delegate permissions in Active Directory
hello all,
i have temporary technician comes once in while work us.i want delegate following permissions day day support tasks:-
1)reset users password
2)unlock user accounts
3)join computers our domain , remove computers our domain
all our user kept under "ou=staff" , our computer accounts kept under "ou=computers"
i don't want give other unnecessary permissions technician on other ou's, domain controller windows 2008.
can please me how task.
regards,
you see wiki started here permissions delegation in ad: http://social.technet.microsoft.com/wiki/contents/articles/20292.delegation-of-administration-in-active-directory.aspx
to delegate unlocking user accounts: http://windowsitpro.com/security/q-how-can-i-delegate-right-unlock-locked-active-directory-ad-user-accounts
to delegate reset of users password: http://community.spiceworks.com/how_to/1464-how-to-delegate-password-reset-permissions-for-your-it-staff
to delegate joining computers domain: https://robiulislam.wordpress.com/2012/02/07/delegate-non-admin-account-to-add-workstations-to-domain/
to delegate removing computers domain: http://sigkillit.com/2013/06/12/delegate-adddelete-computer-objects-in-ad/
in case delegating moving ad objects here go: http://social.technet.microsoft.com/wiki/contents/articles/20747.delegate-moving-user-group-and-computer-accounts-between-organizational-units-in-active-directory.aspx
this posting provided no warranties or guarantees , , confers no rights.
ahmed malek
my website link my linkedin profile my mvp profile
Windows Server > Directory Services
Comments
Post a Comment