Results 1 to 2 of 2
  1. #1
    Lounger
    Join Date
    Apr 2001
    Location
    Glasgow, Lanarkshire, Scotland
    Posts
    36
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Devolved admin in Active Directory

    Hi,

    We have multiple sites in our organisation (c50). We also have a mix of hardware standards (meaning different naking conventions). We have a central IT resource based at head office. We have "IT Champions" on every site that are our 'eyes and ears' - i.e. very useful people to have!

    I want to be able to allow them limted access to Active Directory so that they can only change the descriptions on each machine within their site.

    Anyone know how this would be possible?

  2. #2
    Platinum Lounger
    Join Date
    Jan 2001
    Location
    Quedgeley, Gloucester, England
    Posts
    5,333
    Thanks
    0
    Thanked 1 Time in 1 Post

    Re: Devolved admin in Active Directory

    I use ADUC 'remotely' from my PC, some 6 metres from our server, but just how easy it would be to 'tie down' its use to simply changing computer descriptions, I do not know. You could change the Properties -> Security on the Computers container, but probably you'd need one of these new-fangled GPOs to deny access to anything else. Probably StuartR is your man here?

    John
    <font face="Script MT Bold"><font color=blue><big><big>John</big></big></font color=blue></font face=script>

    Ita, esto, quidcumque...

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •