General discussion


Limiting AD Functions

By jrslyrics ·
Is there a way to limit the functionality of AD Admins. I want to assign a specific group the ability to change and reset passwords, but nothing else.

This conversation is currently closed to new comments.

Thread display: Collapse - | Expand +

All Comments

Collapse -

by CG IT In reply to Limiting AD Functions

use the delegation of authority wizard

This question is typically found on Administering Active Directory Services tests [ for W2K this would be test 70-217].They usually have 2 or 3 questions pertaining to delegating authority for administration of OU in Active Directory.

Collapse -

by hitchcock4 In reply to Limiting AD Functions

He is correct - Delegation of Authority makes sense for limiting the security access.

Another item that I have found useful in the past is to either (1) limit what a manager "sees" (make it easier for him to manage), or (2) limit what a junior administrator "sees" in terms of the overall Organization Unit structure.

One can limit the views and tasks by creating what is called a custom Taskpad.

Two articles you can read on this procedure are at:

Collapse -

by ppigeon In reply to Limiting AD Functions

Are you still looking for solutions aroung AD? If so, please email me directly at

Related Discussions

Related Forums