Hi Paul,
Thank you for the posting. As you indicated you would like to deny delete
user.
Generally speeaking, only domain administrator has the authority to delete
user acount. if you do not want the user to delete user account, you need
to remove the user from the domain administrator group and then delete the
specific right to the user group so that they have other rights and
permission.
Usually, if you cannot restrict some user rights, you can remove the user
from the group such as removing from the administrator group and then
delegate specific right and permission to the user. Some times, elevating
user privileges is easier to implement than restricting user privileges.
In order to allow a user to do this action and only this action you will
need to delegate the USERACCOUNTCONTROL attribute (Both read and Write) on
the OU or container that the user account you with to have disabled exists.
HOW TO: Delegate Administrative Authority in Windows 2000
http://support.microsoft.com/?kbid=315676
Hope the above information and suggestion helps and answers your question.
If anything is unclear, please let me know.
Sincerely,
Cherry Qian
MCSE2000, MCSA2000, MCDBA2000
Microsoft Partner Online Support
Get Secure! -
www.microsoft.com/security
====================================================
When responding to posts, please Reply to Group via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided AS IS with no warranties, and confers no rights.