Delegate control to allow user to be move between OU
We are running Windows 2008 R2 fully native. What permission do I apply to allow only a group the ability to move users between OU?
September 1st, 2010 8:12pm
Here are the permissions required:
Source OU:
Write All Properties
Delete User Objects
Destination OU:
Create User Objects
Delegate the control on the Source and Destination OUs to the wanted group using the persmissions I gave you.
This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
September 1st, 2010 9:59pm
You need
create the object permission in the destination OU and
delete the object permission in the source OU.Santhosh Sivarajan | MCTS, MCSE (W2K3/W2K/NT4), MCSA (W2K3/W2K/MSG), CCNA, Network+ Houston, TX http://blogs.sivarajan.com/ http://publications.sivarajan.com/ This posting is provided "AS IS" with no warranties, and confers no rights.
September 1st, 2010 10:42pm
that works - but that give them the ability to create user account. Is it possible to restrict them from creating accounts?
Free Windows Admin Tool Kit Click here and download it now
September 1st, 2010 10:48pm
It is not possible because to achieve your goal you should delegate Create User Objects permission to the group which will allow the creation of user accounts.
This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
September 1st, 2010 10:52pm