Delegate control to allow user to be move between OU
We are running Windows 2008 R2 fully native. What permission do I apply to allow only a group the ability to move users between OU?
September 1st, 2010 8:12pm

Here are the permissions required: Source OU: Write All Properties Delete User Objects Destination OU: Create User Objects Delegate the control on the Source and Destination OUs to the wanted group using the persmissions I gave you. This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
September 1st, 2010 9:59pm

You need create the object permission in the destination OU and delete the object permission in the source OU.Santhosh Sivarajan | MCTS, MCSE (W2K3/W2K/NT4), MCSA (W2K3/W2K/MSG), CCNA, Network+ Houston, TX http://blogs.sivarajan.com/ http://publications.sivarajan.com/ This posting is provided "AS IS" with no warranties, and confers no rights.
September 1st, 2010 10:42pm

that works - but that give them the ability to create user account. Is it possible to restrict them from creating accounts?
Free Windows Admin Tool Kit Click here and download it now
September 1st, 2010 10:48pm

It is not possible because to achieve your goal you should delegate Create User Objects permission to the group which will allow the creation of user accounts. This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
September 1st, 2010 10:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics