0% found this document useful (0 votes)
22 views5 pages

Active Directory Control Delegation Guide

The document outlines the steps for delegating permissions in Active Directory, including Organizational Unit (OU) permissions, unlocking accounts, password resets, and user account creation. Each section provides a detailed, step-by-step guide for administrators to follow in order to grant specific rights without giving full domain admin access. This process enhances security and efficiency in managing user accounts and permissions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
22 views5 pages

Active Directory Control Delegation Guide

The document outlines the steps for delegating permissions in Active Directory, including Organizational Unit (OU) permissions, unlocking accounts, password resets, and user account creation. Each section provides a detailed, step-by-step guide for administrators to follow in order to grant specific rights without giving full domain admin access. This process enhances security and efficiency in managing user accounts and permissions.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Delegate Control –

Steps for Delegating OU Permissions –


Right click on OU and select Delegate Control --> Select Group you want to
delegate the control to --> Create a custome task to delegate --> This folder,
existing objects in the folder *** --> Tick General/Creation-Deletion of specifc
child objects --> scroll down to the bottom and select "Create/Delete
Organizational Units"

Steps for Delegating the Unlock Account


Rights -
1. Open “Active Directory Users and Computers”

2. Right-click the Organizational Unit or domain in “Active Directory


Users and Computers”. From the context menu, select “Delegate
Control”

3. “Delegation of Control” wizard opens up. Click Next on the


Welcome dialog box to proceed
4. Click “Add” to select the user/group to which the right will be
assigned. Type the name of user or group you want to add and
click “Check Names” button to verify it

Click “OK”.
This takes you back to the wizard. Click “Next” to go to the next page.

5. In this step, you will have to choose the tasks. Select the 2nd
radio button, Create a custom task to delegate, and click Next

6. Select the 2nd option, which is Only the following objects in the
folder. Select User objects in the list, and click Next
7. Select the Property-specific checkbox and ensure that only this
checkbox is selected

In the Permissions list, check both the Read lockoutTime and Write
lockoutTime boxes, and click Next.

8. On the Completing the Delegation of Control Wizard dialog box,


click Finish to close the wizard
Steps for Delegating the Password reset
permission –

Delegated password reset permission for your helpdesk


Nov 25, 2016 (Last updated on July 3, 2020)
This may come as a surprise to some, but you don’t need to grant domain
admin rights for common administrative tasks, like unlocking accounts
and resetting passwords. There’s a better way, and it is so easy, you’ll
wonder why you haven’t done it all along.

1. Open Active Directory Users and Computers.


2. Right-click on the user or group you want to delegate, and
click Delegate Control…
3. Click Next on the Welcome Wizard.
4. Click Add… and enter the user name or group name that will be
granted reset permission. (E.g. ExampleDomain\Helpdesk)
5. Click OK once you’ve made your selection, followed by Next.
6. Ensure that Delegate the following common tasks is enabled, and
select Reset user passwords and force password change at next
logon.
7. Click Next, and Finish.
8. Right-click on the newly modified user or group, and
select Properties.
9. Select the Security tab, and click Advanced.
[Link] Add.
[Link] Select a principal and enter the user name or group name that
has been granted reset permission.
[Link] OK.
[Link] the Applies to field, select Descendant User object.
[Link] down and enable, Read lockoutTime, and Write lockoutTime.
[Link] OK three times.
Steps for Delegating user account creation
permission –

1. Right click the OU. Go to properties. Switch to security tab.


2. Click on "Advanced". In permissions tab, click on Add and select the
account/group to which you want to give "create user" permissions and
click on OK.
3. Now the select the account in "permissions entries:" that you just
added and click on "edit.
4. Ensure that "Apply onto" has "This object only" and now go down the
permissions list till you find "Create User Object" and check that
box(ensure you haven't disturbed any read-only permissions that
accounts gets by default).
5. Click OK and you are set.

You might also like