Re: Custom Delegation in AD

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 10/03/04


Date: Sun, 03 Oct 2004 12:26:47 -0400

You can set up a proxy system where the admin contacts a web page or uses some
tool that can do the work on the admins behalf.

   joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
kusdjeff wrote:
> You said that you cannot set that natively.  Is there any way that you can do 
> it?
> 
> Thanks, Jeff
> 
> "Joe Richards [MVP]" wrote:
> 
> 
>>You can't natively. The delegation has to be to the entire attribute or not at all.
>>
>>
>>
>>--
>>Joe Richards Microsoft MVP Windows Server Directory Services
>>www.joeware.net
>>
>>
>>
>>kusdjeff wrote:
>>
>>>I have a question about AD delegation.  I am in the process of creating an AD 
>>>custom delegation (modifying the delegwiz.inf).  I am able to set all the 
>>>rights for my environment except one.  How do I enable (delegate) my users 
>>>the ability to enable/disable accounts.  I understand that there is a 
>>>'userAccountControl' option, but this grants too many rights.  I only want my 
>>>users the ability to enable/disable accounts without affecting other rights 
>>>such as "Password Never Expires" and "User Cannot Change Password".  How do I 
>>>go about doing this??
>>>
>>>Thanks in advance, Jeff
>>


Relevant Pages

  • Re: Admin rights over OU
    ... User Account Manage on page 34 and ... Microsoft supplies a delegwiz.inf (replace delegation control template ... pretty much encompasses what each admin, junior admin, and specialty groups ... need w/out giving them domain admin rights*. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegation
    ... Hope this helps but make sure uve got full admin rights cos one of the ... delegation rights I gave my admin guy does not allow him to change access ... > What do I click to get to the security option you are referring to? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Admin rights over OU
    ... > delegation on the supplied templates a snap. ... > pretty much encompasses what each admin, junior admin, and specialty groups ... > need w/out giving them domain admin rights*. ...
    (microsoft.public.windows.server.active_directory)
  • Custom Delegation in AD
    ... I have a question about AD delegation. ... but this grants too many rights. ... users the ability to enable/disable accounts without affecting other rights ... such as "Password Never Expires" and "User Cannot Change Password". ...
    (microsoft.public.windows.server.security)
  • Re: Custom Delegation in AD
    ... The delegation has to be to the entire attribute or not at all. ... I understand that there is a> 'userAccountControl' option, but this grants too many rights. ... I only want my> users the ability to enable/disable accounts without affecting other rights> such as "Password Never Expires" and "User Cannot Change Password". ...
    (microsoft.public.windows.server.security)