Delegating permission using group policy


hi,

im system admin in company, , there support employees. want grant these employees permission have local admin rights on computers , authority add users domain, don't want them able create or delete usres, or edit group policies( domain admin not option)

how can using group policy?

hi,

if want grant local admin permission on computers specific users in domain, try configure restricted group setting via group policy. refer detailed steps described in following article try configure gpo.

how make domain user local administrator pcs

http://social.technet.microsoft.com/wiki/contents/articles/7833.how-to-make-domain-user-as-a-local-administrator-for-all-pcs.aspx

in addition, achieve target via powershell. details, please refer article below.

how can add domain user local administrators group?

http://blogs.technet.com/b/heyscriptingguy/archive/2004/10/08/how-can-i-add-a-domain-user-to-a-local-administrators-group.aspx

if want grant domain admin permission specific, such adding users domain, try use delegate control wizard achieve target.

to delegate administrative authority using delegation wizard

  1. right-click container or ou , select delegate control. delegation of control wizard welcome page displayed.
  2. click next. users or groups page displayed.
  3. on users or groups page, click add. select users, computers, or groups page displayed.
  4. on select users, computers, or groups page, in enter object names select box, type name of user or security group want delegate tasks. can add multiple users or security groups. when finished entering users or groups, click ok.
  5. on users or groups page, click next.
  6. on tasks delegate page, select check boxes of tasks want delegate. can create custom task delegate, described later in appendix.
  7. once have selected tasks want delegate, click next. delegation of control wizard displays summary of tasks delegated.
  8. click finish complete delegation.

for details, please refer following article.

appendix g: active directory delegation tools

http://technet.microsoft.com/en-us/library/cc756087(v=ws.10).aspx

regarding detailed information restricted group, suggest refer microsoft kb article below, may useful us.

restricted groups

http://technet.microsoft.com/en-us/library/cc785631(ws.10).aspx

regards,

andy



Windows Server  >  Group Policy



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS