Use the ADUC snap-in to delegate control to that group and create a workpad for them that only offers the choices you want them to see.
Chris Green -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Pennell, Ronald B. Sent: Monday, February 25, 2002 8:34 AM To: '[EMAIL PROTECTED]' Subject: [ActiveDir] Giving Non-Administrators rights to changing user info I would like to be able to give certain admin rights to a group of people (help desk, level 1 support) that can: (1) change user password (2) unlock user account (3) list user information (4) join workstations to the domain Is there an easy way to do this, without curropting the AD? One of my administrators running under NT 4.0 uses some scripts that will do this , ie. chuser, resetpassword, unlock... are they safe to use with W2K? Thanks Ron Pennell [EMAIL PROTECTED] List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/ List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
