• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Server 2003 Active Directory

RucHee

Member
Hey guys, I recently put my Domain Active Directory tool on my Citrix server so someone who is off-site can edit (create) users in a specific group. I would like them to be able to edit that group, but not have access to the entire domain. I don't want to come to work one day and find that they deleted every user on our domain, so I wish to limit her ability as an Active Directory Admin.

Any ideas?

Thanks!
 
Management of objects listed in Active Directory can be delegated to other administrators. Administrative authority cannot be delegated for objects smaller than the Organizational Unit (OU). There are two ways to delegate object control

1 - Find the object in the Active Directory Users and Computers tool, right click on the object, and select "Delegate Control". The Delegation of Control Wizard will start.
2 - Perform the same action as is done when configuring permissions by using the "View" menu in the Active Directory Users and Computers tool, and click on "Advanced Features".
 
Yup. Read up on Active Directory Delegation. This can also be done at the OU level, so you don't have to give somebody rights in areas of the Domain that they don't need authority to change.
 
Thanks for the replies. I was able to find the delegate control area, and i filled out the fields, etc, but when i login as that user, it still allows me to access the rest of the domain. I've delegated a certain group to a certain section, and limited access, but it still lets them see everything / edit everything. Any ideas? Thanks.
 
Back
Top