User rights

Archived from groups: microsoft.public.win2000.active_directory (More info?)

I have domain admins group with few presonnel , I need to
find a way to otorgate rights to a special user (it could
be Account Operator ) to create, move , reset
passwords,enable disable account, in the active directory
(Users and Computers) without give him full rights like
(Domain Admin)

I was trying to create a console.msc and apply a taskpad
view but i got problems when the user use the console he
doesn't has rights.

Thanks any comments
1 answer Last reply
More about user rights
  1. Archived from groups: microsoft.public.win2000.active_directory (More info?)

    You need to 'delegate control' to this user. This basically means that you
    need to set the appropriate permissions on whatever containers you need this
    user to access.

    For example, in order to move a user object between two OUs underneath an OU
    called UK you would grant the user create OU and delete OU permissions on
    the UK OU.

    You can simplify the process using the delegation of control wizard for a
    number of tasks.

    Exactly what tasks do you wish to delegate and at what level?


    --

    Paul Williams

    http://www.msresource.net/
    http://forums.msresource.net/

    "Misaro" <anonymous@discussions.microsoft.com> wrote in message
    news:2ac501c51376$ad7d0ed0$a401280a@phx.gbl...


    I have domain admins group with few presonnel , I need to
    find a way to otorgate rights to a special user (it could
    be Account Operator ) to create, move , reset
    passwords,enable disable account, in the active directory
    (Users and Computers) without give him full rights like
    (Domain Admin)

    I was trying to create a console.msc and apply a taskpad
    view but i got problems when the user use the console he
    doesn't has rights.

    Thanks any comments
Ask a new question

Read More

Domain Consoles Active Directory Windows