Re: Junior Admin

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 12/09/03


Date: Tue, 09 Dec 2003 01:07:34 GMT

They would only be able to use that delegated right on users in that OU that are not
also in the administrators group or other elevated groups. If you want to remove that
permission, you will have to go into the security properties for that OU, find it,
and delete it. You probably will find the entry in advanced/special permissions. --
Steve

"eric" <anonymous@discussions.microsoft.com> wrote in message
news:043901c3bdca$55d32410$a101280a@phx.gbl...
> We want to create a group of "junior admins" and allow
> them to reset passwords and pretty much nothing else. I
> create a group and put members in it, then I created a
> MMC with just to OU and its children in it for "junior
> admins". I then used the delegate wizard and added this
> group to change and reset passwords group. My question
> is, where are these permissions being applies, what do I
> do if in 6 weeks I want to revoke this authority? Where
> is this being set?
> .
>
>



Relevant Pages

  • Re: Limit user access in SBS2003
    ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on Exchange technical issues. ... |> delegated permissions from the parent container. ... |> To delegate the permissions to change user's title, phone number, fax, ...
    (microsoft.public.windows.server.sbs)
  • Re: Delegate Control... Reset Passwords
    ... You can force replication to make the changes immediately to all DCs. ... want that Admins keep the users password. ... that Read and Write permissions in pwdLastSet attribute. ... >>> goal is to reset passwords for users in selected OU's, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delgation of control above the OU grants additional rights which provide Full Control for the us
    ... NewAdmin goes to this web site and requests the change. ... When you allow a user to create an OU, that user is the> owner of that OU and hence can change permissions on the OU. ... >>- to delegate the ability to create, rename and delete Computers in>>the created OUs. ... >>NewAdmin delegates Full Control to BadUser over ...
    (microsoft.public.win2000.setup_deployment)
  • Re: Delgation of control above the OU grants additional rights which provide Full Control for the us
    ... NewAdmin goes to this web site and requests the change. ... When you allow a user to create an OU, that user is the> owner of that OU and hence can change permissions on the OU. ... >>- to delegate the ability to create, rename and delete Computers in>>the created OUs. ... >>NewAdmin delegates Full Control to BadUser over ...
    (microsoft.public.win2000.security)
  • Re: Delgation of control above the OU grants additional rights which provide Full Control for the us
    ... NewAdmin goes to this web site and requests the change. ... When you allow a user to create an OU, that user is the> owner of that OU and hence can change permissions on the OU. ... >>- to delegate the ability to create, rename and delete Computers in>>the created OUs. ... >>NewAdmin delegates Full Control to BadUser over ...
    (microsoft.public.win2000.active_directory)