filmov
tv
Delegate permissions to one account to create, modify, delete in an OU in Windows Server 2016
Показать описание
Delegate permissions to one account to create, modify, delete in an OU in Windows Server 2016
1. Prepare
2. Step by step : Allow HiepIT create, modify, delete in HR OU
- DC1 : Configure allow HiepIT to remote to Domain Controller and create, modify, delete in HR OU
+ Enable remote desktop
+ Click 'File Explorer' - Right-Click 'This PC' - Properties - Remote settings - Choose 'Allow remote connections to this computer' - OK
+ Double-click "Remote Desktop Users" - Members tab - Add... : HiepIT
+ Double-click "Server Operators" - Members tab - Add... : HiepIT (or add to one of groups : Account Operators, Backup Operators, Print Operators)
- Windows Settings - Security Settings - Local Polices - User Rights Assignment - Allow log on through Remote Desktop Services :
+ Tick "Define these policy settings" + Click "Add User or Group..." - Browse... : Administrators;HiepIT - OK
+ Start - cmd - gpupdate /force
+ Active Directory Users and Computers - Right-click HR OU - Delegate Control... :
+ Users or Groups : Add... : HiepIT - Tasks to Delegate : Choose "Delegate the following common tasks" : Tick all (or you want) - Finish
- WIN101 : Remote to DC1 use HiepIT, test create account
+ Right-click IT OU === have not permission
+ Right-click HR OU - New - User - Create Test account === OK
Комментарии