Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , ,

Sponsored Links



Delegate control in ADUC

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 28-10-2008
Cyborg
 
Posts: n/a
Delegate control in ADUC

Hi,

I have 3 domain admins that I only want to allow them to:

Create users
Reset passwords
Mange group membership
Add computer to domain
See all details really.

I just don't want them to be able to create OU's or move them is this
possible?

Reply With Quote
  #2  
Old 28-10-2008
Jorge de Almeida Pinto [MVP - DS]
 
Posts: n/a
Re: Delegate control in ADUC

yes, that is possible.

to start have a look at:
http://blogs.dirteam.com/blogs/jorge...01/05/369.aspx

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* How to ask a question --> http://support.microsoft.com/?id=555375
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------

"Cyborg" <apollo13@btinternet.com> wrote in message
news:29D1F891-3FE3-4D65-87D9-DC7D8E02896A@microsoft.com...
> Hi,
>
> I have 3 domain admins that I only want to allow them to:
>
> Create users
> Reset passwords
> Mange group membership
> Add computer to domain
> See all details really.
>
> I just don't want them to be able to create OU's or move them is this
> possible?


Reply With Quote
  #3  
Old 29-10-2008
Meinolf Weber
 
Posts: n/a
Re: Delegate control in ADUC

Hello Cyborg,

Yes, as said in your subject, Delegate control wizard is your friend for
this.

See here about it:
http://technet.microsoft.com/en-us/l.../cc778807.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> I have 3 domain admins that I only want to allow them to:
>
> Create users
> Reset passwords
> Mange group membership
> Add computer to domain
> See all details really.
> I just don't want them to be able to create OU's or move them is this
> possible?
>



Reply With Quote
  #4  
Old 30-10-2008
Cyborg
 
Posts: n/a
Re: Delegate control in ADUC

Can they still remain in the domain admins group and have this restriction?


"Jorge de Almeida Pinto [MVP - DS]"
<SubstituteThisWithMyFullNameSeparatedByDots@gmail.com> wrote in message
news:eSvn0$ROJHA.1960@TK2MSFTNGP04.phx.gbl...
> yes, that is possible.
>
> to start have a look at:
> http://blogs.dirteam.com/blogs/jorge...01/05/369.aspx
>
> --
>
> Cheers,
> (HOPEFULLY THIS INFORMATION HELPS YOU!)
>
> # Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #
>
> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
> ------------------------------------------------------------------------------------------
> * How to ask a question --> http://support.microsoft.com/?id=555375
> ------------------------------------------------------------------------------------------
> * This posting is provided "AS IS" with no warranties and confers no
> rights!
> * Always test ANY suggestion in a test environment before implementing!
> ------------------------------------------------------------------------------------------
> #################################################
> #################################################
> ------------------------------------------------------------------------------------------
>
> "Cyborg" <apollo13@btinternet.com> wrote in message
> news:29D1F891-3FE3-4D65-87D9-DC7D8E02896A@microsoft.com...
>> Hi,
>>
>> I have 3 domain admins that I only want to allow them to:
>>
>> Create users
>> Reset passwords
>> Mange group membership
>> Add computer to domain
>> See all details really.
>>
>> I just don't want them to be able to create OU's or move them is this
>> possible?

>


Reply With Quote
  #5  
Old 30-10-2008
Meinolf Weber
 
Posts: n/a
Re: Delegate control in ADUC

Hello Cyborg,

No, you can not restrict domain admins.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Can they still remain in the domain admins group and have this
> restriction?
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@gmail.com> wrote in
> message news:eSvn0$ROJHA.1960@TK2MSFTNGP04.phx.gbl...
>
>> yes, that is possible.
>>
>> to start have a look at:
>> http://blogs.dirteam.com/blogs/jorge...01/05/369.aspx
>> --
>>
>> Cheers,
>> (HOPEFULLY THIS INFORMATION HELPS YOU!)
>> # Jorge de Almeida Pinto # MVP Identity & Access - Directory Services
>> #
>>
>> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
>> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
>> ---------------------------------------------------------------------
>> ---------------------
>> * How to ask a question --> http://support.microsoft.com/?id=555375
>> ---------------------------------------------------------------------
>> ---------------------
>> * This posting is provided "AS IS" with no warranties and confers no
>> rights!
>> * Always test ANY suggestion in a test environment before
>> implementing!
>> ---------------------------------------------------------------------
>> ---------------------
>> #################################################
>> #################################################
>> ---------------------------------------------------------------------
>> ---------------------
>> "Cyborg" <apollo13@btinternet.com> wrote in message
>> news:29D1F891-3FE3-4D65-87D9-DC7D8E02896A@microsoft.com...
>>
>>> Hi,
>>>
>>> I have 3 domain admins that I only want to allow them to:
>>>
>>> Create users
>>> Reset passwords
>>> Mange group membership
>>> Add computer to domain
>>> See all details really.
>>> I just don't want them to be able to create OU's or move them is
>>> this possible?
>>>



Reply With Quote
  #6  
Old 30-10-2008
Cyborg
 
Posts: n/a
Re: Delegate control in ADUC

Hi,

I'm following the wizard but I don't see an option which would stop users
create OU's, moving OU's.


"Meinolf Weber" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb66c1db8cb0767269b82fa@msnews.microsoft.com...
> Hello Cyborg,
>
> Yes, as said in your subject, Delegate control wizard is your friend for
> this.
>
> See here about it:
> http://technet.microsoft.com/en-us/l.../cc778807.aspx
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Hi,
>>
>> I have 3 domain admins that I only want to allow them to:
>>
>> Create users
>> Reset passwords
>> Mange group membership
>> Add computer to domain
>> See all details really.
>> I just don't want them to be able to create OU's or move them is this
>> possible?
>>

>
>


Reply With Quote
  #7  
Old 31-10-2008
Meinolf Weber
 
Posts: n/a
Re: Delegate control in ADUC

Hello Cyborg,

You use the wizard to allow explicit some configuration. Any other option
should be denied, if they are only domain users. Basically any domain user
can only read in AD, nothing more. Test it before activating in a test environment.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> I'm following the wizard but I don't see an option which would stop
> users create OU's, moving OU's.
>
> "Meinolf Weber" <meiweb(nospam)@gmx.de> wrote in message
> news:ff16fb66c1db8cb0767269b82fa@msnews.microsoft.com...
>
>> Hello Cyborg,
>>
>> Yes, as said in your subject, Delegate control wizard is your friend
>> for this.
>>
>> See here about it:
>> http://technet.microsoft.com/en-us/l.../cc778807.aspx
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Hi,
>>>
>>> I have 3 domain admins that I only want to allow them to:
>>>
>>> Create users
>>> Reset passwords
>>> Mange group membership
>>> Add computer to domain
>>> See all details really.
>>> I just don't want them to be able to create OU's or move them is
>>> this
>>> possible?



Reply With Quote
  #8  
Old 31-10-2008
Jorge de Almeida Pinto [MVP - DS]
 
Posts: n/a
Re: Delegate control in ADUC

no of course not! if they only need to do this, WHY would they need to stay
members of domain admins group? that's just weird, isn't it?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* How to ask a question --> http://support.microsoft.com/?id=555375
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------

"Cyborg" <apollo13@btinternet.com> wrote in message
news:FCE891E8-348F-4DEC-9AF7-6B8E854BC94D@microsoft.com...
> Can they still remain in the domain admins group and have this
> restriction?
>
>
> "Jorge de Almeida Pinto [MVP - DS]"
> <SubstituteThisWithMyFullNameSeparatedByDots@gmail.com> wrote in message
> news:eSvn0$ROJHA.1960@TK2MSFTNGP04.phx.gbl...
>> yes, that is possible.
>>
>> to start have a look at:
>> http://blogs.dirteam.com/blogs/jorge...01/05/369.aspx
>>
>> --
>>
>> Cheers,
>> (HOPEFULLY THIS INFORMATION HELPS YOU!)
>>
>> # Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #
>>
>> BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
>> BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
>> ------------------------------------------------------------------------------------------
>> * How to ask a question --> http://support.microsoft.com/?id=555375
>> ------------------------------------------------------------------------------------------
>> * This posting is provided "AS IS" with no warranties and confers no
>> rights!
>> * Always test ANY suggestion in a test environment before implementing!
>> ------------------------------------------------------------------------------------------
>> #################################################
>> #################################################
>> ------------------------------------------------------------------------------------------
>>
>> "Cyborg" <apollo13@btinternet.com> wrote in message
>> news:29D1F891-3FE3-4D65-87D9-DC7D8E02896A@microsoft.com...
>>> Hi,
>>>
>>> I have 3 domain admins that I only want to allow them to:
>>>
>>> Create users
>>> Reset passwords
>>> Mange group membership
>>> Add computer to domain
>>> See all details really.
>>>
>>> I just don't want them to be able to create OU's or move them is this
>>> possible?

>>

>

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Delegate control in ADUC"
Thread Thread Starter Forum Replies Last Post
Remote Control from ADUC tkutil Active Directory 2 22-03-2010 10:18 PM
Delegate Control of OU in AD 2008 Roger McCarrick Active Directory 1 05-02-2010 06:32 PM
Delegate control of OU aconti Active Directory 2 06-11-2009 12:39 AM
Delegate Control to rename and add/remove computer from domain Flash3200 Windows Security 4 01-03-2007 10:41 PM
Delegate Control to users to update own Personal Information Colin Active Directory 9 03-11-2005 04:47 AM


All times are GMT +5.5. The time now is 01:57 AM.