Advanced Delegation Settings in AD DS 2008 R2
hi !
i have big network including 2 major sites
each site has own support staff there common groups because settings internet sharing , ... done centrally in main office
i have 2 questions, 1 general , 1 more specific
the second :
i have groups members should changed support team. example groups internet usage. point : each support team should able add or remove members in own ou.
let me clarify this
there ou named ou-branch1 , 1 named ou-branch2
there group not in of them (of course can put in 1 of them if must). every 1 in group has 20mb internet traffic per day.
support teams in both branches should able add or remove member group, important condition. can users in own related ou !!
and more general question : please give me link or adocument know advanced , detailed settings , permissions can set in delegation settings
thanks
instead of having single group in main office.you can create 2 group 1 in ou-branch1 , other in ou-branch2 and delegate control add/remove user group.
https://www.soton.ac.uk/isolutions/computing/auth/activedirectory/group.html
http://www.grouppolicy.biz/2010/09/how-to-delegate-ad-permission-to-organisational-units-using-the-powershell-command-add-qadpermission/
how delegate basic server administration junior administrators.
http://support.microsoft.com/kb/555986
best practices delegating active directory administration
http://www.microsoft.com/en-us/download/details.aspx?id=21678
best regards,
sandesh dubey.
mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator | blog
disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment