Can't move EXISTING computer objects in AD


suddenly our delegated helpdesk folks having problems moving computers 'access denied'.  i've verified create, delete, , write attribs has been delegated on affected ou branches group containing of users affected.

with cloned test account in group i can create, delete, , move computer accounts (that create) .  there some existing accounts refuse moved short of domain admin.

this working , bit stumped.  had 1 case 'protect accidental deletion' flag @ fault - not main culprit idt.


hi,

posting in microsoft technet forums.

please check suggestions in thread below see if can helpful in situation:

delegate control of ou 

http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f1d6d833-f3d1-4ef9-a717-1f685e99b1a2/#a27472ee-b7a4-4f2c-90c8-2048a98d696b

delegate control move user objects 1 ou ou 

http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f6f751fd-1b83-4cb1-a5f5-62a552e7ac36/

have nice day.

regards

kevin 


Windows Server  >  Security



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Invalid pointer on gpresult /h gpreport.html