Baboon
2008-03-14 16:54:01 UTC
I am trying to delegate permissions to a group for moving existing computer
objects between several OUs. KB932455 is probably one article among many
that tells how to delegate permissions for adding computers to an OU. These
are the settings from the article:
************************************************************
6. In the Tasks to Delegate page, click Create a custom task to delegate,
and then click Next.
7. Click Only the following objects in the folder, and then from the list,
click to select the following check boxes:
• Computer objects
• Create selected objects in this folder
• Delete selected objects in this folder
8. Click Next.
9. In the Permissions list, click to select the following check boxes:
• Reset Password
• Validated write to DNS host name
• Read and write Account Restrictions
• Validated write to service principal name
************************************************************
After following those instruction, users in that group can create and delete
new computer objects in the respective OUs but cannot move existing computer
objects or ones they created within those same OUs.
Can someone tell me which permissions I need to add for users to move
computers between these OUs?
Thanks.
objects between several OUs. KB932455 is probably one article among many
that tells how to delegate permissions for adding computers to an OU. These
are the settings from the article:
************************************************************
6. In the Tasks to Delegate page, click Create a custom task to delegate,
and then click Next.
7. Click Only the following objects in the folder, and then from the list,
click to select the following check boxes:
• Computer objects
• Create selected objects in this folder
• Delete selected objects in this folder
8. Click Next.
9. In the Permissions list, click to select the following check boxes:
• Reset Password
• Validated write to DNS host name
• Read and write Account Restrictions
• Validated write to service principal name
************************************************************
After following those instruction, users in that group can create and delete
new computer objects in the respective OUs but cannot move existing computer
objects or ones they created within those same OUs.
Can someone tell me which permissions I need to add for users to move
computers between these OUs?
Thanks.