Re: Delegate Authority



Domain Admins is protected from delegatation with the adminsdholder functionality, you can move that group into any OU you want and the delegation in that OU will not allow someone to modify the group. However, it is best practice to not delegate the OU holding high level IDs and groups to admins with lesser rights.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


Les Arrowman wrote:
I brought up the great idea of removing the help desk folks from the Domain Admins group. I want to delegate certain roles to the HD folks by putting them in group named 'SupportAdmins' or something similar.

If I give this group add/remove group memberships for an OU, say 'Organization' which then has all the subOU's for the various departments. I do NOT want the group inside the Organization OU as then have the ability to kick eachother out of the group or attempt to add the SupportAdmins groups to the Domain Admins group again correct? (Someone before I got here moved the DomAdm group to the Organization OU)

In other words, should I make an OU outside of Organization named 'Delegates' and create the SupportAdmins group in there.
.



Relevant Pages

  • Re: Remove Domain Admins ability from "Delegation Of Control"
    ... Domain Admins and administrators are very powerfull groups. ... There is no point of having a group that would only be able to delegate all ... Then i plan on removing the the Read Members, ... > modify the restricted group membership to this "restricted group ...
    (microsoft.public.win2000.active_directory)
  • Re: Different Sites - One Database ?
    ... Create one site and delegate the necessary permissions to the different ... permissions to the child sites to the respective domain admins. ... MVP SMS ...
    (microsoft.public.sms.setup)
  • Re: Delegation of Authority in an OU
    ... Delegate Administrative Authority in Windows 2000. ... > The steps outlined here will also work within Windows Server 2003. ... > delegated permissions does NOT need to be a member of the Domain Admins ... > group or any similar administrative group. ...
    (microsoft.public.windows.server.active_directory)
  • replication monitoring rights
    ... We have recently gone through a strict security measure and removed ... pretty much everyone from domain admins and started to delegate every ... user account. ... not longer domain admins, BUT, have full delegation to their users? ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegate Authority
    ... You should delegate group membership control at some OU and then ... > kick eachother out of the group or attempt to add the SupportAdmins groups ...
    (microsoft.public.win2000.security)