Delegate control for account operators on domain admin accounts
Hi,
I need to allow account operators to be able to unlock domain admins accounts. Is this possible?
Thanks,
James.
October 2nd, 2012 4:27am
Hello,
to control domain admins use domain admins and NOT lower permissioned accounts.Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
October 2nd, 2012 4:41am
Hello,
to control domain admins use domain admins and NOT lower permissioned accounts.Best regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
October 2nd, 2012 4:55am
Thanks. Interestingly, I've found a solution. I gave a user whose access is lower than domain admin "full control" access under user's properties and this did the trick.
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2012 3:02am
Thanks. Interestingly, I've found a solution. I gave a user whose access is lower than domain admin "full control" access under user's properties and this did the trick.
Note that modifying the ACL on a Domain Admin account isn't permanent - permissions over these accounts are controlled by the AdminSDHolder object in Active Directory. Your PDC Emulator will reset the ACL on these accounts with the ACL on the AdminSDHolder
object on a regular basis. This is done to prevent tampering with privileged accounts in your AD forest. Here is some more information that is a pretty decent read: http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx
Edit: Also, I strongly recommend not doing what you are trying to do.
October 4th, 2012 5:41pm
Yes, I found that the permissions were removed a few mins after that. I will have to give this up as I don't think it's possible.
Free Windows Admin Tool Kit Click here and download it now
October 4th, 2012 8:08pm
http://support.microsoft.com/kb/294952
this link shows you to steps of delegation user account or group.Darshana Jayathilake
October 4th, 2012 10:18pm
Hello,
see here about AdminSDHolder and why permissions are reset for specific security groups.
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspxBest regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
October 5th, 2012 4:35am
Hello,
see here about AdminSDHolder and why permissions are reset for specific security groups.
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspxBest regards
Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/
Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
October 5th, 2012 4:38am