Members of Account Operators Group Cannot Manage All User Accounts

M

Mikael Oskarsson

My customer wants to let Members of Account Operators
Manage All other Account Operators

Is it possible?

Regards
 
M

Matjaz Ladava [MVP]

J

Joe Richards [MVP]

You can do it unless you modify adminsdholder which would also give account ops the ability to manipulate your
administrator ID's as well. So the feasible answer is no, not natively. You could write up some proxy system of handling
it like writing a COM+ object running in an administrative context that does that work.
 
J

Joe Richards [MVP]

You know I just realized there is a way you could pull this off. Create the separate OU like Matjaz recommends and set
up the acc op delegation there and then modify the adminsdholder object to have inheritance... I would not recommend
this though as that inheritance being turned off is to protect you in case somehow an admin ID gets moved into an OU
where some normal person has full user delegation given to them or one of several critical attributes delegated to their
control because they could manipulate the admin ID and gain control of the directory.

--
Joe Richards
www.joeware.net
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top