Re: Custom Delegation in AD

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 09/25/04

  • Next message: Karl Levinson [x y] mvp: "Re: Folder Security"
    Date: Fri, 24 Sep 2004 21:37:16 -0400
    
    

    You can't natively. The delegation has to be to the entire attribute or not at all.

    --
    Joe Richards Microsoft MVP Windows Server Directory Services
    www.joeware.net
    kusdjeff wrote:
    > I have a question about AD delegation.  I am in the process of creating an AD 
    > custom delegation (modifying the delegwiz.inf).  I am able to set all the 
    > rights for my environment except one.  How do I enable (delegate) my users 
    > the ability to enable/disable accounts.  I understand that there is a 
    > 'userAccountControl' option, but this grants too many rights.  I only want my 
    > users the ability to enable/disable accounts without affecting other rights 
    > such as "Password Never Expires" and "User Cannot Change Password".  How do I 
    > go about doing this??
    > 
    > Thanks in advance, Jeff
    

  • Next message: Karl Levinson [x y] mvp: "Re: Folder Security"

    Relevant Pages

    • Re: Limiting Access Rights to AD from Windows 2000 Professional
      ... I've done the DELEGATION WIZARD. ... to review user information and change password. ... the user access her MMC console she can make changes to ... Can she have more rights flowing downwards that is ...
      (microsoft.public.win2000.active_directory)
    • Re: Custom Delegation in AD
      ... You can set up a proxy system where the admin contacts a web page or uses some ... The delegation has to be to the entire attribute or not at all. ... but this grants too many rights. ... >>>users the ability to enable/disable accounts without affecting other rights ...
      (microsoft.public.windows.server.security)
    • Re: Limiting Access Rights to AD from Windows 2000 Professional
      ... to do a customize delegation within the wizard. ... > to review user information and change password. ... > the user access her MMC console she can make changes to ... > overwriting the rights on a particular OU? ...
      (microsoft.public.win2000.active_directory)
    • Re: Mapping to W2003 user rights/access?
      ... > when it comes to access/user rights. ... I believe Clustering should need maximum Adminrights on the Cluster. ... > 6) Is there a granular delegation setting or something ... I wouldn't even use Account Operators, ...
      (microsoft.public.windows.server.migration)
    • Re: Delegate control questions
      ... help of Delegation Of Control Wizrad. ... Yes it was a replciation problem, Now I can see all computers ... noticed that if the local admin creates an own mmc with ADUC snap he will ... se the whole AD but have only rights to do something in his OU ...
      (microsoft.public.windows.server.active_directory)