Custom Delegation in AD
From: kusdjeff (kusdjeff_at_discussions.microsoft.com)
Date: 09/23/04
- Next message: Steven L Umbach: "Re: SMB signing"
- Previous message: Karl Levinson [x y], mvp: "RE: Security features to be added in Windows Server 2003 R2?"
- Next in thread: Joe Richards [MVP]: "Re: Custom Delegation in AD"
- Reply: Joe Richards [MVP]: "Re: Custom Delegation in AD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 23 Sep 2004 11:59:03 -0700
I have a question about AD delegation. I am in the process of creating an AD
custom delegation (modifying the delegwiz.inf). I am able to set all the
rights for my environment except one. How do I enable (delegate) my users
the ability to enable/disable accounts. I understand that there is a
'userAccountControl' option, but this grants too many rights. I only want my
users the ability to enable/disable accounts without affecting other rights
such as "Password Never Expires" and "User Cannot Change Password". How do I
go about doing this??
Thanks in advance, Jeff
- Next message: Steven L Umbach: "Re: SMB signing"
- Previous message: Karl Levinson [x y], mvp: "RE: Security features to be added in Windows Server 2003 R2?"
- Next in thread: Joe Richards [MVP]: "Re: Custom Delegation in AD"
- Reply: Joe Richards [MVP]: "Re: Custom Delegation in AD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|