Results 1 to 2 of 2
2006-12-13, 11:27 #1
- Join Date
- Apr 2001
- Glasgow, Lanarkshire, Scotland
- Thanked 0 Times in 0 Posts
Devolved admin in Active Directory
We have multiple sites in our organisation (c50). We also have a mix of hardware standards (meaning different naking conventions). We have a central IT resource based at head office. We have "IT Champions" on every site that are our 'eyes and ears' - i.e. very useful people to have!
I want to be able to allow them limted access to Active Directory so that they can only change the descriptions on each machine within their site.
Anyone know how this would be possible?
2006-12-13, 14:10 #2
- Join Date
- Jan 2001
- Quedgeley, Gloucester, England
- Thanked 1 Time in 1 Post
Re: Devolved admin in Active Directory
I use ADUC 'remotely' from my PC, some 6 metres from our server, but just how easy it would be to 'tie down' its use to simply changing computer descriptions, I do not know. You could change the Properties -> Security on the Computers container, but probably you'd need one of these new-fangled GPOs to deny access to anything else. Probably StuartR is your man here?
John<font face="Script MT Bold"><font color=blue><big><big>John</big></big></font color=blue></font face=script>
Ita, esto, quidcumque...