IT tutorials
 
Applications Server
 

Active Directory 2008 : Managing OUs (part 3) - Delegating Control of OUs

4/24/2014 1:34:02 AM
- Free product key for windows 10
- Free Product Key for Microsoft office 365
- Malwarebytes Premium 3.7.1 Serial Keys (LifeTime) 2019

3. Delegating Control of OUs

In simple environments, one or a few systems administrators may be responsible for managing all of the settings within Active Directory. For example, a single systems administrator could manage all users within all OUs in the environment. In larger organizations, however, roles and responsibilities may be divided among many different individuals. A typical situationis one in which a systems administrator is responsible for objects within only a few OUs inan Active Directory domain. Or, one systems administrator might manage User and Group objects while another is responsible for managing file and print services.

Fortunately, using the Active Directory Users And Computers tool, you can quickly and easily ensure that specific users receive only the permissions they need. In Exercise 2, you will use the Delegation of Control Wizard to assign permissions to individuals.

Exercise 2: Using the Delegation of Control Wizard

  1. Open the Active Directory Users And Computers administrative tool.

  2. Right-click the Corporate OU within the North America OU and select Delegate Control. This starts the Delegation of Control Wizard. Click Next to begin configuring security settings.

  3. In the Users Or Groups page, click the Add button. In the Enter The Object Names To Select field, enter Account Operators and press Enter. Click Next to continue.

  4. In the Tasks To Delegate page, select Delegate The Following Common Tasks and place a check mark next to the following items:

    Create, Delete, And Manage User Accounts

    Reset User Passwords And Force Password Change At Next Logon

    Read All User Information

    Create, Delete, And Manage Groups

    Modify The Membership Of A Group

    Click Next to continue.



  5. The Completing The Delegation of Control Wizard page then provides a summary of the operations you have selected. To implement the changes, click Finish.




Although the common tasks available through the wizard are sufficient for many delegation operations, you may have cases in which you want more control. For example, you might want to give a particular systems administrator permissions to modify only Computer objects. Exercise 3 uses the Delegation of Control Wizard to assign more granular permissions.

Exercise 3: Delegating Custom Tasks

  1. Open the Active Directory Users And Computers administrative tool.

  2. Right-click the Corporate OU within the North America OU and select Delegate Control. This starts the Delegation of Control Wizard. Click Next to begin making security settings.

  3. In the Users Or Groups page, click the Add button. In the Enter The Object Names To Select field, enter Server Operators and press Enter. Click Next to continue.

  4. In the Tasks To Delegate page, select the Create A Custom Task To Delegate radio button, and click Next to continue.

  5. In the Active Directory Object Type page, choose Only The Following Objects In The Folder, and place a check mark next to the following items (you will have to scroll down to see them all):

    User Objects

    Computer Objects

    Contact Objects

    Group Objects

    Organizational Unit Objects

    Printer Objects

    Click Next to continue.



  6. In the Permissions page, place a check mark next to the General option and make sure the other options are not checked. Note that if the various objects within your Active Directory schema had property-specific settings, you would see those options here. Place a check mark next to the following items:

    Create All Child Objects

    Read All Properties

    Write All Properties

    This gives the members of the Server Operators group the ability to create new objects within the Corporate OU and the permissions to read and write all properties for these objects. Click Next to continue.



  7. Click Next to continue.

  8. The Completing The Delegation of Control Wizard page provides a summary of the operations you have selected. To implement the changes, click Finish.

 
Others
 
- Active Directory 2008 : Managing OUs (part 2) - Administering Properties of OUs
- Active Directory 2008 : Managing OUs (part 1) - Moving, Deleting, and Renaming OUs
- Microsoft Lync Server 2013 : Installing the Director Role (part 3) - Install Server
- Microsoft Lync Server 2013 : Installing the Director Role (part 2) - Creating a Director Pool - Edit Topology, Publish Topology
- Microsoft Lync Server 2013 : Installing the Director Role (part 1) - Prerequisites
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 10) - Creating public folder mailboxes
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 9) - Creating shared mailboxes
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 8) - Creating arbitration mailboxes, Creating Discovery mailboxes
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 7) - Creating and using archive mailboxes - Creating online archives, Managing archive settings
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 6) - Creating and using archive mailboxes - Creating in-place archives
 
 
Top 10
 
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Finding containers and lists in Visio (part 2) - Wireframes,Legends
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Finding containers and lists in Visio (part 1) - Swimlanes
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Formatting and sizing lists
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Adding shapes to lists
- Microsoft Visio 2013 : Adding Structure to Your Diagrams - Sizing containers
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 3) - The Other Properties of a Control
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 2) - The Data Properties of a Control
- Microsoft Access 2010 : Control Properties and Why to Use Them (part 1) - The Format Properties of a Control
- Microsoft Access 2010 : Form Properties and Why Should You Use Them - Working with the Properties Window
- Microsoft Visio 2013 : Using the Organization Chart Wizard with new data
Technology FAQ
- Is possible to just to use a wireless router to extend wireless access to wireless access points?
- Ruby - Insert Struct to MySql
- how to find my Symantec pcAnywhere serial number
- About direct X / Open GL issue
- How to determine eclipse version?
- What SAN cert Exchange 2010 for UM, OA?
- How do I populate a SQL Express table from Excel file?
- code for express check out with Paypal.
- Problem with Templated User Control
- ShellExecute SW_HIDE
programming4us programming4us