If you have any long boring tasks that just aren’t worth your time, such as putting in and keeping up with phone numbers for all your users, or addresses, group memberships. or want to push off administration of a mailing list or group off to someone else with more free time. i finally found the solution. the reason i started this is to allow my student worker to manage the crap i dont have time to. specifically the phone numbers of the users in a specific OU. so that’s the example i will use to show how to do this. but the same steps can be used to delegate permissions to just about anyone for anything.
Im going to assume your familiar with active directory and all. so well start with opening AD and finding the OU whos permissions you would like to delegate. mine was called “Awesomepeople”. click on the OU to select it then right click it and select the top choice which is “Delegate Control”.

This is the actual meat and bones part of the operation, deciding what you want the person to control. in my example i only want them to be able to edit phone numbers of users in the “awesome people” OU. after clicking delegate control the next relevant screen is shown below.

there is a list of common tasks you can select to delegate, but to do anything truly awesome and cool you’ll want to create a custom delegation, inorder to only delegate user editing and not password changing or anything else i dont want them to do youll need to go with custom. after hitting next youll get a broad listing of what category of permissions you would like to delegate, in this case its phone numbers which are a part of user objects to i selected user objects.

Depending on what your looking for youll need to check additional boxes, general if its something simple, if you want to refine the delegation and limit the abilities of the person your delegating to i would recommend being as specific as possible. so check em all and narrow it down!

after youve made your selections your done with the time consuming part. now comes the easy part. the user you selected has the ability to control the items you specified in active directory… but they dont have access to active directory! so we need to make a custom MMC (microsoft management console) for them to access only what we let them! to do this click start, then run, then type MMC and hit enter. then click file, add snap in, and add the active directory users and computers snapin. open up the snapin and navigate to the OU that your delegating control of. click the ou to highlight it, then right click it and to go “New Taskpad View”

this part is ridiculously simple. just keep clicking next, when you get to the section with a listing of users youll select the user you want control delegated to, then select the general task your delegating (again in this example its user objects). after that just keep clicking next and your done! well just about, you want to save the snap in to a location where the user can access it. so file save as, and save it someone convenient. thats it! if you have any questions feel free to comment 
November 18th, 2008
Tags: Active Directory, Deligation, Permissions, Windows 2008 Server
Posted in IT . Comments: No Comments