Allowing group membership modifications Active Directory 5.2 and MMS 3.0
I need the office manager to be able to add and delete members from groups. Under properties -> Security -> Permissions, I allowed SELF read and write group membership. She restarted her machine, her group policies changed so that she was now able to add objects (users), but was unable to remove them. She also gets a message saying she doesn't have sufficient permissions. Help? Thanks!
January 3rd, 2008 11:39pm

I think you would need to explicity grant the priviledge of Delete to the user - this is considered a "Special Permission" and can be modified from the "Advanced" security management dialogue. Look for any explicit Deny on the Username or Self objects & change that to allow BEFORE adding new ALLOW Permissions.
Free Windows Admin Tool Kit Click here and download it now
January 5th, 2008 1:18am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics