Professional Documents
Culture Documents
eu
MENU
Our goal here is to delegate permissions for creating, deleting, moving, modifying computer objects in
specified OU by specified group without being given full control over the object or OU.
Go to OU Properties -> Security -> Advanced -> Add, then select principal (group or user you want to delegate
permissions to), type – Allow.
Permissions Tab
Apply onto This object and all descendant objects
Create Computer objects
Delete Computer objects
Permissions Tab
Apply onto Descendant Computer Objects
List Contents
Read All Properties
Delete
Delete Subtree
Read Permissions
All Validated Writes
All Extended Rights
http://ijustdoit.eu/addelegatepermissionstoadddeletemovecomputerobjects/ 1/4
16/5/2016 AD – Delegate Permissions To Add / Delete / Move / Modify Computer Objects | I Just Do IT.eu
Properties Tab
Apply onto Descendant Computer Objects
Write Account Restrictions
Write Computer name (pre-Windows 2000)
Write Description
Write msDS-User-Account-Control-Computed
Write msDS-UserPasswordExpiryTimeComputed
Write userParameters
Read Personal Information
Write Personal Information
Read Public Information
Write Public Information
http://ijustdoit.eu/addelegatepermissionstoadddeletemovecomputerobjects/ 2/4
16/5/2016 AD – Delegate Permissions To Add / Delete / Move / Modify Computer Objects | I Just Do IT.eu
If you want to delegate only move permissions, apply only these settings which are marked with green color
above. Remember that it has to be done on both – source and destination OU.
Share this:
Like this:
Like
Be the first to like this.
Comments
One reply
Anonymous REPLY
DECEMBER 24, 2015 AT 5:45 PM
When i go to effective permissions to check settings im still getting a red X on Delete Computer
objects. any help would be great thanks!
Leave a Reply
http://ijustdoit.eu/addelegatepermissionstoadddeletemovecomputerobjects/ 3/4
16/5/2016 AD – Delegate Permissions To Add / Delete / Move / Modify Computer Objects | I Just Do IT.eu
Enter your comment here...
http://ijustdoit.eu/addelegatepermissionstoadddeletemovecomputerobjects/ 4/4