Here is my idea, Fred

Open up ADUC and click View / Advanced Features. Right click on that one OU where he should only be allowed to change the passwords of the users and choose Properties. Click Security tab, click Advanced button. Scroll down to highlight OU. Click it and choose Edit. Here you can give the contractor ability to change or reset passwords.

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of van Donk, Fred
Sent: 20 Септември 2005 г. 23:52
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] Domain Controller Security

 

I have a contractor in a remote site. There is only 1 server in that site which is a DC.

 

He needs to administer that server.

-Create shares

-Make file/share permissions

-Change user passwords in the User OU for that site.

 

He is not allowed to log on to any other server is the domain.

 

When I make him a "Server Operator" he can logon to any server in the domain.

 

Any idea on how to lock him down to that one server and then how to lock him down on that one OU where he should only be allowed to change the passwords of the users.

 

Thanks!

Fred

 

 

Reply via email to