
Active Directory Administration Cookbook, Second Edition
By :

In large Active Directory environments, administration may be challenging. Therefore, in environments with several teams of administrators and service desk personnel, delegation can be quite helpful. This way, just to name a few possibilities, service desk personnel may reset passwords, application administrators may change group memberships, and only true Active Directory admins may manage OUs.
To perform delegation of control, sign in with an account that is a member of the Domain Admins group or has full control privileges of the OU you want to delegate control over.
This recipe describes two ways to delegate control over an OU:
By far the easiest way to perform delegation of control is using the Delegation of Control Wizard from Active Directory Users and Computers (dsa.msc
). Perform...