What I meant was, I had first tried delegating a security group with the Create/Delete User Object with Full Permissions. When this didn't work, I then remove the permissions and tried delegating the 'Create, Delete & Manage User Account' right with F/C
 
When I look at the Security Tab of the existing users, my security group is not listed as a member, but new accounts which I have created do which explains my issue.
 
How can I ensure my security group exists in the security tab of all of the user objects within the OU so they have access?
 


Jose Medeiros <[EMAIL PROTECTED]> wrote:
I may be mistaken, but it sounds to me like you need to recursively reset the permissions of the existing objects within that OU.
 
Jose
----- Original Message -----
To: Active
Sent: Thursday, August 25, 2005 1:45 AM
Subject: [ActiveDir] OU permissions for user object

Hi,
 
I've created an OU and I have delegated a security group the Create/Delete User Object with Full Permissions.
 
I have also delegated the 'Create, Delete & Manage User Account' right with F/C
 
I only want this security group to be able to manage user accounts in this OU and modify the users details/group membership.
 
The problem I have is that I can't enable/disable a user or modify the user's details on an account which already exists.
 
If I create a new account, I can do all the delegated tasks set, but on existing accounts I get error messages such as "you have insufficient rights to perform this operation" or the details are greyed out. 
 
Any idea's where I can check?
 
Iain

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

Reply via email to