Tech Support > Operating Systems > Windows 2003 > AD Administration
AD Administration
Posted by Clippy on February 11th, 2004


Hi I need to start evaluated tools to administer our AD
users/groups etc but I don't want to give the helpdesk
access to either the AD Users and Computers MMC or a
custom version. Can anyone recommend some good 3rd party
tool sets?

Thanks in advance

Posted by Mike Brannigan [MSFT] on February 11th, 2004


"Clippy" <anonymous@discussions.microsoft.com> wrote in message
news:e67f01c3f0b2$4f9055d0$a001280a@phx.gbl...
Why are you reluctant to give the helpdesk ADUC or a customer version?
If you have delegated and secured the objects correctly then they should not
be able to do anything untoward.
Or is this a functionality issue with the ADUC tool ?

--
Regards,

Mike
--
Mike Brannigan [Microsoft]

This posting is provided "AS IS" with no warranties, and confers no
rights

Please note I cannot respond to e-mailed questions, please use these
newsgroups

"Clippy" <anonymous@discussions.microsoft.com> wrote in message
news:e67f01c3f0b2$4f9055d0$a001280a@phx.gbl...


Posted by Chriss3 on February 11th, 2004


I think you want to use the Delegate Control Wizard do define rights for
your helpdesk.

Step-by-Step Guide to Using the Delegation of Control Wizard:
http://www.microsoft.com/windows2000...delegsteps.asp

--
Regards,

Christoffer Andersson
No email replies please - reply in the newsgroup
If the information was help full, you can let me know at:
http://www.itsystem.se/employers.asp?ID=1

"Clippy" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:e67f01c3f0b2$4f9055d0$a001280a@phx.gbl...


Posted by Craig on February 11th, 2004


80,000 user objects and specialised accounts requiring additonal
functionality is the simple answer. We do secure the AD but have a
requirement to only allow the HDesk viewable acces to the objects they
adminster. We currently give them a custoum ADUC with taskpads that call out
to in-house scripts. We need to get away from the scripts.
"Mike Brannigan [MSFT]" <mikebran@online.microsoft.com> wrote in message
news:eFcFFQL8DHA.1640@TK2MSFTNGP11.phx.gbl...



Similar Posts