General discussion

Locked

Limiting AD Functions

By jrslyrics ·
Is there a way to limit the functionality of AD Admins. I want to assign a specific group the ability to change and reset passwords, but nothing else.

This conversation is currently closed to new comments.

3 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

by CG IT In reply to Limiting AD Functions

use the delegation of authority wizard

This question is typically found on Administering Active Directory Services tests [ for W2K this would be test 70-217].They usually have 2 or 3 questions pertaining to delegating authority for administration of OU in Active Directory.

Collapse -

by hitchcock4 In reply to Limiting AD Functions

He is correct - Delegation of Authority makes sense for limiting the security access.

Another item that I have found useful in the past is to either (1) limit what a manager "sees" (make it easier for him to manage), or (2) limit what a junior administrator "sees" in terms of the overall Organization Unit structure.

One can limit the views and tasks by creating what is called a custom Taskpad.

Two articles you can read on this procedure are at:
http://www.winsupersite.com/showcase/win2k_taskpad.asp
and
http://www.petri.co.il/create_taskpads_for_ad_operations.htm

Collapse -

by ppigeon In reply to Limiting AD Functions

Are you still looking for solutions aroung AD? If so, please email me directly at ppigeon@netpro.com

Back to Networks Forum
3 total posts (Page 1 of 1)  

Related Discussions

Related Forums