Delegate permissions in Active Directory


hello all,
i have temporary technician comes once in while work us.i want delegate following permissions day day support tasks:-

1)reset users password

2)unlock user accounts

3)join computers our domain , remove computers our domain

all our user kept under "ou=staff" , our computer accounts kept under "ou=computers" 

i don't want give other unnecessary permissions technician on other ou's, domain controller windows 2008.

can please me how task.

regards,


you see wiki started here permissions delegation in ad: http://social.technet.microsoft.com/wiki/contents/articles/20292.delegation-of-administration-in-active-directory.aspx

to delegate unlocking user accounts: http://windowsitpro.com/security/q-how-can-i-delegate-right-unlock-locked-active-directory-ad-user-accounts

to delegate reset of users password: http://community.spiceworks.com/how_to/1464-how-to-delegate-password-reset-permissions-for-your-it-staff

to delegate joining computers domain: https://robiulislam.wordpress.com/2012/02/07/delegate-non-admin-account-to-add-workstations-to-domain/

to delegate removing computers domain: http://sigkillit.com/2013/06/12/delegate-adddelete-computer-objects-in-ad/

in case delegating moving ad objects here go: http://social.technet.microsoft.com/wiki/contents/articles/20747.delegate-moving-user-group-and-computer-accounts-between-organizational-units-in-active-directory.aspx


this posting provided no warranties or guarantees , , confers no rights.

ahmed malek

my website link

my linkedin profile

my mvp profile



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Invalid pointer on gpresult /h gpreport.html