Here are some of the most commonly delegated administrative tasks in Active Directory -
- Creation and deletion of domain user accounts
- Resetting domain user account passwords
- Disabling and enabling of domain user accounts
- Unlocking domain user accounts
- Creation and deletion of domain security groups
- Changing domain security group memberships
- Changing domain security group scopes
- Changing domain security group types
- Creation and deletion of organizational units
- Linking and unliking of GPOs to organizational units
- Creation and deletion of service connection points
- Changing a service connection point keywords
This comment has been removed by the author.
ReplyDeleteHi James,
ReplyDeleteHope you are well and that work's going well. Hey, I might have found something you might find quite valuable.
Came across an Active Directory report tool called Gold Finger, that had these access reports which could be used to determine who is delegated what access in Active Directory.
Since you're focused on delegation in AD, thought it might be helpful to you.
If you get a chance to try it or review it, I'd be interested in your thoughts on it.
Cheers,
Marc