What Permissions to give a user who needs to look after AD Users & Computers Windows Server 2008


hi all

i need assign permissions desk users allow them remove 'group memberships' in 'member of' in ad & uc in server 2008, in server 2003 have given them 'power users', 2008 cannot this

i don't want them having domain admin rights need them able delete network folders along above

any suggesstions great

thanks

hello,

for delegation start with:

http://www.windowsecurity.com/articles/implementing-active-directory-delegation-administration.html in example inside article can see option "modify membership of group"

http://jorgequestforknowledge.wordpress.com/2006/05/16/delegation-of-control-how/

http://jorgequestforknowledge.wordpress.com/2006/01/05/creating-a-taskpad-and-delegating-several-admin-tasks/


best regards

meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/

disclaimer: posting provided no warranties or guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...