delegation of control
i hoping give desktop support rights check off property of distribution group. “managers can update membership list”.
they have rights delegation control.
you chose delegate control of objects
in following active directory folder:
domain.local/
the groups, users, or computers you
have given control are:
it_usersonly_gr (cmp\it_usersonly_gr)
they have following permissions:
read
write
write properties
for following object types:
contact
group
user
if try modify existing object groups under security read managedby , write managedby allow , out of ad , check allow property removed.
any ideas how enforce?
hi,
in test, have read, write, write properties privilege not enough modify group permission, permission check box grayed out , can’t modify.
after grant full control permission delegated account, can modify security tab groups, can grant read managedby , write managedby permission. notice that, after apply modification, create new entry object, store newly add permission, not in old object entry, since newly add permission inherited form “not inherited”. please check that.
for more information please refer following ms article:
delegating administration
http://technet.microsoft.com/en-us/library/cc778807(v=ws.10).aspx
delegation of control wizard
http://technet.microsoft.com/en-us/library/dd145344.aspx
lawrence
technet community support
Windows Server > Directory Services
Comments
Post a Comment