Principle of least privilege - Delegate rights to move between OUs - Active Directory

  • Thread starter Thread starter Johnny14752
  • Start date Start date
J

Johnny14752

Guest
Hi, I´ve been having trouble delegating rights to a non-admin user. He should have to be able to move Computer Objects between delegated OU´s with minimum rights. I got the following solution working: - Delegate a custom Task, on source and destination OU- Applied to: only Computer Objects in a folder, including Create/Delete selected Objects in this folder - Permissions: Write All Properties Now the part that is bothering us, the "Write all Properties" Flag... Respecting the Principle of least privilege we would like to apply only the necessary and mandatory Write Permissions for Pr

Continue reading...
 
Back
Top