Delegating Administrative
Control in Active Directory
- Larger organizations require many more administrators to manage specific domains, OUs, or containers or even specific objects within OUs or containers.
- To ensure that administrators receive the appropriate permissions, we must delegate the administration of the domain, OU, or container by using the Delegation Of Control Wizard.
Pages in the Delegation Of Control Wizard
1. Users Or Groups Page:
Enables to select the user accounts or groups for
Delegation
2. Tasks To
Delegate Page: Enables to select the tasks to
delegate.
3. Active
Directory Object Type Page: Enables to select the objects for
delegation
4. Permissions
Page: Enables you to select one of the available
permissions
to
delegate
Steps for delegation of control
1.
Click Start, select Administrative
Tools, and then click Active Directory Users And Computers.
2.
Right-click the appropriate
domain, OU, or container, and then click Delegate
Control.
3.
On the Welcome To The Delegation
Of Control Wizard page, click Next.
4.
On the Users Or Groups page, shown
in Figure, click Add.
5.
In the Select Users, Computers, Or
Groups dialog box, type the user or group for which you want to delegate
administration in the Enter The Object Names To Select box, and then click OK. Click Next on
the Users Or Groups page.
6.
To delegate any of the tasks
listed in the box, click Delegate The Following Common Tasks and select the appropriate
tasks. Click Next.
7.
On the Active Directory Object Type page, select one of the available options
as shown below:
8.
On the Permissions page, select one of the options available:
9. Select the appropriate permissions you
want to assign to the users or groups for the container or objects in the
Permissions box, and then click Next.
10. On the Completing The Delegation Of
Control Wizard page, review your selections.
Click Finish.