DELEGATION CONTROL, WHAT IS IT ALL ABOUT?
The process of decentralizing management tasks of OU.
Assigning management task of an OU to another user or groups.
Eases the load of a system administrator by dividing the administration jobs.
Assigning management task of an OU to another user or groups.
Eases the load of a system administrator by dividing the administration jobs.
APPLYING DELEGATION RIGHTS TO OU USERS
- Login DC as an admin and open ADUC console.
- Select any OU to which you want to delegate the control to (E.g. MARKETING) and select the user to whom you want to give the control and hit Next.
- Give him some task you think that he\she can manage and is required in your absence. We will check ‘Create, Delete and manage user accounts’ and finish the wizard.
VERIFICATION
Login domain controller with M1 account. The reason to login into DC is we get the ADUC console (use CMDLET dsa.msc) only on the DC and not on the client computers.
Now, try creating some AD users in MARKETING OU, you will now be able to do that since, you have been given delegation control by system administrator to manage only that particular OU.
Comments
Post a Comment