Delegate permissions in Active Directory


hello all,
i have temporary technician comes once in while work us.i want delegate following permissions day day support tasks:-

1)reset users password

2)unlock user accounts

3)join computers our domain , remove computers our domain

all our user kept under "ou=staff" , our computer accounts kept under "ou=computers" 

i don't want give other unnecessary permissions technician on other ou's, domain controller windows 2008.

can please me how task.

regards,


you see wiki started here permissions delegation in ad: http://social.technet.microsoft.com/wiki/contents/articles/20292.delegation-of-administration-in-active-directory.aspx

to delegate unlocking user accounts: http://windowsitpro.com/security/q-how-can-i-delegate-right-unlock-locked-active-directory-ad-user-accounts

to delegate reset of users password: http://community.spiceworks.com/how_to/1464-how-to-delegate-password-reset-permissions-for-your-it-staff

to delegate joining computers domain: https://robiulislam.wordpress.com/2012/02/07/delegate-non-admin-account-to-add-workstations-to-domain/

to delegate removing computers domain: http://sigkillit.com/2013/06/12/delegate-adddelete-computer-objects-in-ad/

in case delegating moving ad objects here go: http://social.technet.microsoft.com/wiki/contents/articles/20747.delegate-moving-user-group-and-computer-accounts-between-organizational-units-in-active-directory.aspx


this posting provided no warranties or guarantees , , confers no rights.

ahmed malek

my website link

my linkedin profile

my mvp profile



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS