Can't move EXISTING computer objects in AD


suddenly our delegated helpdesk folks having problems moving computers 'access denied'.  i've verified create, delete, , write attribs has been delegated on affected ou branches group containing of users affected.

with cloned test account in group i can create, delete, , move computer accounts (that create) .  there some existing accounts refuse moved short of domain admin.

this working , bit stumped.  had 1 case 'protect accidental deletion' flag @ fault - not main culprit idt.


hi,

posting in microsoft technet forums.

please check suggestions in thread below see if can helpful in situation:

delegate control of ou 

http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f1d6d833-f3d1-4ef9-a717-1f685e99b1a2/#a27472ee-b7a4-4f2c-90c8-2048a98d696b

delegate control move user objects 1 ou ou 

http://social.technet.microsoft.com/forums/en-us/winserversecurity/thread/f6f751fd-1b83-4cb1-a5f5-62a552e7ac36/

have nice day.

regards

kevin 


Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS