delegation of control


i hoping give desktop support rights check off property of distribution group. “managers can update membership list”.

they have rights delegation control.

you chose delegate control of objects
in following active directory folder:

    domain.local/

the groups, users, or computers you
have given control are:

    it_usersonly_gr (cmp\it_usersonly_gr)

they have following permissions:

    read
    write
    write properties

for following object types:

    contact
    group
    user

if try modify existing object groups under security read managedby , write managedby allow , out of ad , check allow property removed.

any ideas how enforce?

hi,

in test, have read, write, write properties privilege not enough modify group permission, permission check box grayed out , can’t modify.

after grant full control permission delegated account, can modify security tab groups, can grant read managedby , write managedby permission. notice that, after apply modification, create new entry object, store newly add permission, not in old object entry, since newly add permission inherited form “not inherited”. please check that.

for more information please refer following ms article:

delegating administration
http://technet.microsoft.com/en-us/library/cc778807(v=ws.10).aspx
delegation of control wizard
http://technet.microsoft.com/en-us/library/dd145344.aspx


lawrence

technet community support



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL