Re: Delegate Authority
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Thu, 15 Dec 2005 21:20:04 -0700
You should delegate group membership control at some OU and then
have within that OU (or its subOUs) only the groups which you want to
allow those delegated to control (mve the rest of the groups elsewhere).
--
Roger Abell
Microsoft MVP (Windows Server : Security)
"Les Arrowman" <LesArrowman@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4E7659EF-132F-46BD-B2C4-828F83634F21@xxxxxxxxxxxxxxxx
>I brought up the great idea of removing the help desk folks from the Domain
> Admins group. I want to delegate certain roles to the HD folks by putting
> them in group named 'SupportAdmins' or something similar.
>
> If I give this group add/remove group memberships for an OU, say
> 'Organization' which then has all the subOU's for the various departments.
> I
> do NOT want the group inside the Organization OU as then have the ability
> to
> kick eachother out of the group or attempt to add the SupportAdmins groups
> to
> the Domain Admins group again correct? (Someone before I got here moved
> the
> DomAdm group to the Organization OU)
>
> In other words, should I make an OU outside of Organization named
> 'Delegates' and create the SupportAdmins group in there.
.
- Prev by Date: Re: Folder creator owner
- Next by Date: Re: AD-Fu a bit rusty so a small sec question
- Previous by thread: Re: Delegate Authority
- Index(es):
Relevant Pages
|
|