Delegate control for account operators on domain admin accounts
Hi, I need to allow account operators to be able to unlock domain admins accounts. Is this possible? Thanks, James.
October 2nd, 2012 4:27am

Hello, to control domain admins use domain admins and NOT lower permissioned accounts.Best regards Meinolf Weber MVP, MCP, MCTS Microsoft MVP - Directory Services My Blog: http://msmvps.com/blogs/mweber/ Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
October 2nd, 2012 4:41am

Hello, to control domain admins use domain admins and NOT lower permissioned accounts.Best regards Meinolf Weber MVP, MCP, MCTS Microsoft MVP - Directory Services My Blog: http://msmvps.com/blogs/mweber/ Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
October 2nd, 2012 4:55am

Thanks. Interestingly, I've found a solution. I gave a user whose access is lower than domain admin "full control" access under user's properties and this did the trick.
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2012 3:02am

Thanks. Interestingly, I've found a solution. I gave a user whose access is lower than domain admin "full control" access under user's properties and this did the trick. Note that modifying the ACL on a Domain Admin account isn't permanent - permissions over these accounts are controlled by the AdminSDHolder object in Active Directory. Your PDC Emulator will reset the ACL on these accounts with the ACL on the AdminSDHolder object on a regular basis. This is done to prevent tampering with privileged accounts in your AD forest. Here is some more information that is a pretty decent read: http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx Edit: Also, I strongly recommend not doing what you are trying to do.
October 4th, 2012 5:41pm

Yes, I found that the permissions were removed a few mins after that. I will have to give this up as I don't think it's possible.
Free Windows Admin Tool Kit Click here and download it now
October 4th, 2012 8:08pm

http://support.microsoft.com/kb/294952 this link shows you to steps of delegation user account or group.Darshana Jayathilake
October 4th, 2012 10:18pm

Hello, see here about AdminSDHolder and why permissions are reset for specific security groups. http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspxBest regards Meinolf Weber MVP, MCP, MCTS Microsoft MVP - Directory Services My Blog: http://msmvps.com/blogs/mweber/ Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
October 5th, 2012 4:35am

Hello, see here about AdminSDHolder and why permissions are reset for specific security groups. http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspxBest regards Meinolf Weber MVP, MCP, MCTS Microsoft MVP - Directory Services My Blog: http://msmvps.com/blogs/mweber/ Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
October 5th, 2012 4:38am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics