I've been asked to stir up the hornets nest....

Soldato
Joined
7 Jun 2003
Posts
16,131
Location
Gloucestershire
Via the means of removing a current domain admins access rights and only very specific tasks available to them...

Before this is rolled out to the user in question i have to make sure that various tasks such as adding PCs to the domain, managing users in active directory etc aren't affected.

I've got the file access area covered quite well so that they can read and/or write to specific places going by the security groups I've got them in, but now I'm at the point where i need to lock down active directory so that they can manage users, maybe computers (not sure on that yet), but certainly not manage things like the domain admins group.

I've only ever done an all or none setup with this before so need guidance here, the other problem I've got is that i need them to have a small amount of access to group policy, is it possible to give specific group policy access rights...for example not being able to change policies but being able to read them and change who they apply to?

Thanks for any help with this, though I'm dreading the reaction when it's implemented.
 
indeed, very easy to do. Delegate certain tasks to certain groups and add them to users to those groups as appropriate.
 
One word of caution. There isn't an un-delegate wizard, be very careful what changes you make as they can take some time to rectify if something goes wrong.
 
One word of caution. There isn't an un-delegate wizard, be very careful what changes you make as they can take some time to rectify if something goes wrong.

Thank you for the warning, is there a planning/testing feature for this at all?
 
Yes its called a lab :D

If you dont have a lab apply it to a test OU at least. You can see that all the wizard is really doing is changing the ACL on the target object.
 
Yes its called a lab :D

If you dont have a lab apply it to a test OU at least. You can see that all the wizard is really doing is changing the ACL on the target object.

The mere idea of having a lab in this place is laughable :p Having the time or even server space (or even the physical space) would be a nice luxury that i have no chance of.

EDIT: actually i do have an old HP DL320 G5 i could put ESXi on but it's so time consuming i'm not sure i'd have time to do it all :(
 
Last edited:
Can you not just use Active Directory Administrative Center, right click the domain admins group --> properties --> extensions --> browse/add the user --> give use read privileges of the group only?

Screenshot:
2zsqiqq.png
 
Thank you for the warning, is there a planning/testing feature for this at all?

As others have suggested either a lab / test domain, at the very least use a test OU with some test accounts.
Also, as already mentioned technet is your friend, take the time to read up, digest, test and document.

If your company has money and willingness to invest (which I get the feeling the haven't by your post) then there's 3rd party applications to help you with delegation also which can make this a lot easier, and safer.
 
Back
Top Bottom