Delegate permissions to one account to create, modify, delete in an OU in Windows Server 2016

preview_player
Показать описание

Delegate permissions to one account to create, modify, delete in an OU in Windows Server 2016

1. Prepare

2. Step by step : Allow HiepIT create, modify, delete in HR OU

- DC1 : Configure allow HiepIT to remote to Domain Controller and create, modify, delete in HR OU

+ Enable remote desktop

+ Click 'File Explorer' - Right-Click 'This PC' - Properties - Remote settings - Choose 'Allow remote connections to this computer' - OK

+ Double-click "Remote Desktop Users" - Members tab - Add... : HiepIT

+ Double-click "Server Operators" - Members tab - Add... : HiepIT (or add to one of groups : Account Operators, Backup Operators, Print Operators)

- Windows Settings - Security Settings - Local Polices - User Rights Assignment - Allow log on through Remote Desktop Services :

+ Tick "Define these policy settings" + Click "Add User or Group..." - Browse... : Administrators;HiepIT - OK

+ Start - cmd - gpupdate /force

+ Active Directory Users and Computers - Right-click HR OU - Delegate Control... :

+ Users or Groups : Add... : HiepIT - Tasks to Delegate : Choose "Delegate the following common tasks" : Tick all (or you want) - Finish

- WIN101 : Remote to DC1 use HiepIT, test create account

+ Right-click IT OU === have not permission

+ Right-click HR OU - New - User - Create Test account === OK

Рекомендации по теме
Комментарии
Автор

How to restrict AD users internet access until they login to VPN and control browser??

ranjithkumargujja