Saturday, November 28, 2015

Adding Delegated Permissions with the Wizard

  1. Open the Active Directory Users and Computers console.
  2. Right-click the All Users OU and choose Delegate Control, as shown in Figure 1. Click the Next button to advance past the wizard's welcome page.
Figure 1: Starting the Delegation of Control Wizard

  1. On the wizard's Users or Groups page, click the Add button.
  2. In the Select Users, Computers, or Groups dialog box, enter the group's name (Password Reset), click the Check Names button to make sure the group's name is correct, and click OK, as shown in Figure 2.
Figure 2: Entering the Group's Name
Figure 2: Entering the Group's Name

  1. After making sure the group's name is listed on the Users or Groups page, click Next, as shown in Figure 3.
Figure 3: Making Sure the Group's Name Is Listed
Figure 3: Making Sure the Group's Name Is Listed

  1. On the Tasks to Delegate page, select Reset user passwords and force password change at next logon and click Next, as shown in Figure 4.
Figure 4: Selecting the Tasks to Delegate
Figure 4: Selecting the Tasks to Delegate

  1. Verify the information in the final page of the wizard and click Finish.
When you click the Finish button, the Delegation of Control Wizard adds the requested permissions to the All Users OU. You can view the effects of the delegation by right-clicking the All Users OU, choosing Properties, and selecting the Security tab. (If the Security tab isn't visible, enable the Advanced Features option on the View menu of the Active Directory Users and Computers console.) For a detailed view, you can click the Advanced button. Figure 5 shows the Advanced Security Settings dialog box that appears.



Figure 5: Reviewing the DACL for the All Users OU
Figure 5: Reviewing the DACL for the All Users OU

No comments:

Post a Comment