How to Delegate Control in Active Directory Users and Computers
In this article we’ll learn the steps to delegate control in Active Directory Users and Computers. In Organizations, delegate control is given to the help-desk representative to perform the tasks of reset password, add computer or server in domain, create new user, etc. In a domain, domain administrator is a user who can perform all operations and tasks related to domain and Active Directory. Domain Administrator is a member of Domain Admins group and also a user who is not available 24 x 7 x 365. So, the question is when the domain administrator is not available then who will manage the Active Directory.
First option is that, we will add any other user into the Domain Admins group. This would assign Domain Admin permissions to the newly added user, these rights are sufficient to perform any domain level change in the environment. But do you really want to give keys of kingdom to anyone? In my opinion, this is not the right way of delegating control.
There is an another option of Delegate Control using Active Directory Users and Computers, through which we can deploy customized access and permissions for the domain users. Through this, users can perform the tasks that Administrator is designated to perform.
Steps to Delegate Control to Domain Users
We’ll create group of users, to whom we’ll delegate rights to manage user accounts. It is recommended to delegate access to groups instead of delegating permissions to an individual users.
2. On New Object-Group console, enter the group name, select Global and Security options from the given options in group scope and group type respectively. Click on ok. In this example, we will create a group naming Helpdesk.
5. Right click on the Organizational Unit (Sales) and click on Delegate Control to delegate the customized permissions to the user or a group of users. This wizard will only delegate access for Sales OU and not for other OUs.
6. On the “Delegation of Control Wizard” we can see the relevance of delegate control. We can grant users permission to manage users, computers, groups, OU and other objects of AD Users and Computers. Click on Next to continue.
8. In Tasks to Delegate console, select “delegate the following common tasks” and select permissions from the given tasks. Or select the “Create a custom task to delegate” to give custom permissions to the users other than the above permissions. Click on Next to continue. For this example, we’ll delegate control for “create, delete and manage user accounts” and “Reset user passwords and force password change at next logon”.
A user (TU1) is a member of Helpdesk Group and have delegated permissions. But these rights would not enable domain user to login to Domain Controller. This user cannot access Active Directory Users and Computers either by login to Domain Controller or using RDP from any client machine e.g. Windows 8.1 operating system because he is not a member of Domain Admins group.
To enable user to access Active Directory users and computers from client machine, we need to install the Active Directory Domain Services role on Windows 8.1 client, to install the role, install the windows update package (Windows8.1-KB2693643-x64). You can download this update package from the given link (http://www.microsoft.com/en-us/download/details.aspx?id=39296).
1. After installing this package, we can see the icon of Active Directory Users and Computers in the start menu under Administrative Tools on Windows 8.1 Operating System. Click on the icon of AD Users and Computers to open the console.
2. Through this console, this user (TU01) can only perform the operations that we have delegated to “Helpdesk Group”. Learn how to create user. We will try to create a new user in the Organizational Unit (Sales) to the check that given permissions are delegated successfully or not. Right click on the OU (Sales) and then click on New and then User to create a new user.
3. On New Object – User console, enter the details like First name, Last Name, User logon name of the new user which you want to create. Click on Next to continue.
4. Enter the password in the Password and Confirm Password field of the user which we are creating and select the option according to your requirement from the given options. Click on Next to continue. On the next console verify all the settings and then click on Finish.
5. On Active Directory Users and Computers, in Sales OU we can verify that user tu15 is successfully created. It clearly shows that rights are successfully delegated to the user tu01 through the security group helpdesk.
This user (TU01) can perform other delegated rights e.g. resetting user account password, deleting user account and other similar operations.
Delegate access would enable set of users to perform the tasks that are normally performed by Domain Admins. It would only restrict the user to the OU on which rights are delegated.