can someone tell me how to delegate control to allow a desktop support person to move users objects between OUs without giving sweeping administrative rights?
(From another web site) One of the biggest advantages that Active Directory has over the flat Domain structure in NT 4 and earlier is that domain resources can be organized in a hierarchical tree design. This makes it easy to group users, computers, and other resources. Within AD, there is a wizard called the "Delegation of Control" Wizard. This tool will enable you to safely and easily delegate certain tasks to certain users within a specified Organizational Unit. To start the tool, simply right-click an OU in the Active Directory Users and Computers MMC window. Choose "Delegate Control..." and the wizard will start. From there just follow the prompts to choose which users you will delegate control to, and which actions you will be allowing them to perform.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.