User attributes question

Archived from groups: microsoft.public.win2000.active_directory (More info?)

If I want to enable a security group to be able to disable user accounts in
AD, what user object attribute do I need to allow the group to change so
they have permissions to disable users? thanks in advance!

Phil Nunn
2 answers Last reply
More about user attributes question
  1. Archived from groups: microsoft.public.win2000.active_directory (More info?)

    This article may help:

    http://www.microsoft.com/WINDOWS2000/techinfo/reskit/deploymentscenarios/scenarios/ou_delegate_admin_authority_secgroups.asp


    Cheers,

    John Powell

    "Philip Nunn" wrote:

    > If I want to enable a security group to be able to disable user accounts in
    > AD, what user object attribute do I need to allow the group to change so
    > they have permissions to disable users? thanks in advance!
    >
    > Phil Nunn
    >
    >
    >
  2. Archived from groups: microsoft.public.win2000.active_directory (More info?)

    They have to have write access to userAccountControl. Note that will give
    additional capabilities. Do a google search for useraccountcontrol and
    enumeration and look at flag enumeration of that attribute.

    joe

    --
    Joe Richards Microsoft MVP Windows Server Directory Services
    www.joeware.net


    Philip Nunn wrote:
    > If I want to enable a security group to be able to disable user accounts in
    > AD, what user object attribute do I need to allow the group to change so
    > they have permissions to disable users? thanks in advance!
    >
    > Phil Nunn
    >
    >
Ask a new question

Read More

Microsoft User Accounts Active Directory Windows