Limited Access to ADU&C for HR?

  • Thread starter Thread starter Rube
  • Start date Start date
R

Rube

Hi All,

I would like to offload everyday management of security group & user
maintenance to a member of our HR team who was a network admin in a previous
life. This person would be allowed to use Active Directory Users & Computers
to add new users & change group memberships in the domain, as well as change
file & folder security in the HR file server. I would prefer not to make
them a domain admin obviously. . .

Any recommendations or caveats? Anyone else do this? What permissions do I
have to give this HR person to allow them to accomplish the above tasks?

TIA,
Rube
 
Hello Rube,
Take use of the Delegate of Control Wizard.

See the Step-by-Step Guide to Using the Delegation of Control Wizard
This guide shows how to delegate control of objects in an Active Directory
service container, using the Delegation of Control wizard in the Active
Directory Users and Computers snap-in.

http://www.microsoft.com/windows2000/techinfo/planning/activedirectory/delegsteps.asp


--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services

No email replies please - reply in the newsgroup
 
Back
Top