Windows 2003 R2 delegated permissions are not available for some users in an OU



Created a group called HelpDesk that will allow those users to unlock
an account via a custom MMC console. The group HelpDesk has four IT
members in it. In AD Users and Computers, I highlighted the domain and
involked the Delegation of Control wizard. I added the HelpDesk group
and allowed them to 'reset' the password. I then went into the
permissions and checked the Write LockoutTime and ReadLockoutTime
values and saved.

When I look at my Users Accounts OU, the security tab (advanced view)
for all members shows the HelpDesk having special permissions - EXCEPT
for 2 of the accounts. Both of these accounts were part of Domain
Admins some time ago, but have been removed from that account. This
was done before the HelpDesk group was even created. It appears that
once one of my users is part of the Domain Admins group, the delgate
permissions do not apply to them. Is this correct? What can I do to
force the inherited permissons from the OU to apply two my 2 'orphaned
users'? Any helpd would be appreciated.

Thanks,
Mark

.



Relevant Pages

  • Re: Win2k - Account Operator not working properly
    ... The tool is a command line tool from Microsoft to enumerate the permissions on an object. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Helpdesk CAN create new accounts/modify/delete/reset passwords for NEW accounts in OUs beneath the top-level OU. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows 2003 R2 delegated permissions are not available for some users in an OU
    ... To correct the issue for the 2 accounts who are no longer members of any ... for all members shows the HelpDesk having special permissions - EXCEPT ... was done before the HelpDesk group was even created. ...
    (microsoft.public.windows.server.security)
  • Re: Win2k - Account Operator not working properly
    ... Helpdesk CAN create new accounts/modify/delete/reset passwords for NEW accounts in OUs beneath the top-level OU. ... The members of the group can now create/delete/modify NEW user accounts and reset passwords for these accounts, but cannot create/delete/modify/reset passwords for any accounts that existed PRIOR to my running the delegate control wizard.....any ideas on a cause and a fix? ... The proper way to handle this is to create one or more groups and delegate the permissions needed to those groups and add admins to the groups as needed. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problem managing accounts in protected groups
    ... If your normal domain users that manage accounts are aible to manage also the higher level administrators, ... Never heard about that someone will give more security permissions to users then to the admins. ... Most members of OU A are either members of Domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: OU delegation, permission to move but not delete objects
    ... Has anyone tried limiting a group's permissions, say the helpdesk, to only be allowed to create and modify user/computer accounts in a particular OU and sub-OUs, but NOT delete any accounts? ... If you've locked it down like this, can the helpdesk still move accounts between sub OUs? ... I'm checking to see if anyone else has experience/advice before I start researching and experimenting. ...
    (microsoft.public.windows.server.active_directory)