I've been asked to stir up the hornets nest....

Soldato
Joined
7 Jun 2003
Posts
16,131
Location
Gloucestershire
Via the means of removing a current domain admins access rights and only very specific tasks available to them...

Before this is rolled out to the user in question i have to make sure that various tasks such as adding PCs to the domain, managing users in active directory etc aren't affected.

I've got the file access area covered quite well so that they can read and/or write to specific places going by the security groups I've got them in, but now I'm at the point where i need to lock down active directory so that they can manage users, maybe computers (not sure on that yet), but certainly not manage things like the domain admins group.

I've only ever done an all or none setup with this before so need guidance here, the other problem I've got is that i need them to have a small amount of access to group policy, is it possible to give specific group policy access rights...for example not being able to change policies but being able to read them and change who they apply to?

Thanks for any help with this, though I'm dreading the reaction when it's implemented.
 
One word of caution. There isn't an un-delegate wizard, be very careful what changes you make as they can take some time to rectify if something goes wrong.

Thank you for the warning, is there a planning/testing feature for this at all?
 
Yes its called a lab :D

If you dont have a lab apply it to a test OU at least. You can see that all the wizard is really doing is changing the ACL on the target object.

The mere idea of having a lab in this place is laughable :p Having the time or even server space (or even the physical space) would be a nice luxury that i have no chance of.

EDIT: actually i do have an old HP DL320 G5 i could put ESXi on but it's so time consuming i'm not sure i'd have time to do it all :(
 
Last edited:
Back
Top Bottom