User access only 1 OU group but allow add, delete modify for that OU
Trying to lock down OU for a department, but allow one uer to add, delete or modify users and security groups.  Not allow them to see other OUs in AD.
May 22nd, 2015 3:25pm

Hi

 Open Active Directory Users and  Computers, select OU(Which you want to allow user to configure), then right click ->select Delegate Control->add user->Select "Create,delete and manage user accounts" & "Create,delete and manage groups" then follow the steps.

Free Windows Admin Tool Kit Click here and download it now
May 22nd, 2015 4:55pm

Trying to lock down OU for a department, but allow one user to add, delete or modify users and security groups.  Not allow them to see other OUs in AD.

This is actually a better question for the dedicated WinDS forum (it's not really a GP question at all):
https://social.technet.microsoft.com/Forums/en-US/home?forum=winserverDS

You can delegate control of an OU to a user (without granting control to other OUs) as Burak suggests.

You can't (and shouldn't) disallow a user to "see other OUs in AD"...

May 23rd, 2015 11:02pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics