Menu
InformatiWeb Pro
  • Index
  • System admin
  • Virtualization

Login

Registration Password lost ?
FR
  • Windows Server
    • WMS 2012
    • WS2012 R2
    • WS2016
  • Citrix
    • Citrix NetScaler Gateway
    • Citrix XenApp / XenDesktop
    • Citrix XenServer
  • VMware
    • VMware ESXi
    • VMware vSphere
    • VMware Workstation
  • Microsoft
    • Hyper-V
  • RAID
    • Adaptec SmartRAID
  • UPS
    • APC Back-UPS Pro
  • InformatiWeb Pro
  • System admin
  • Windows Server
  • Courses
  • Learn how to deploy Active Directory (AD DS) on WS 2016
  • Create a delegation of control
28 / 32
  • Seize FSMO roles
  • Create forest trust relationships

Create a delegation of control on an Active Directory infrastructure on Windows Server 2016

  • Windows Server
  • 25 June 2021 at 12:15 UTC
  • InformatiWeb
  • 2/2
Previous page

2. Delegate a custom task using the Delegation of Control wizard

To delegate a custom task, open the Delegation of Control wizard.

Choose the users and/or groups to whom you want to delegate the task.

This time, we will delegate the task to our IT Manager.

This time, select "Create a custom task to delegate".

In the "Active Directory object type" step, you can choose to delegate control of all types of objects that are in the desired folder or only specific types of objects.
In our case, we are going to delegate control only on "Organizational Unit" and "User" type objects, and we authorize it to :

  • create selected objects in this folder
  • delete selected objects in this folder

3. Managed by

Another faster way to delegate control of a read-only domain controller (RODC) or group, for example, is to use the "Managed by" tab.
For example, below, we delegate the management of the "MySecurityGroup" group to our IT Manager by allowing him to update the list of members.

4. Manually manage Active Directory permissions

The last possibility is to delegate specific tasks or allow specific actions on specific types of objects to specific users and to go through the "Security" tab of the desired container.
Right click "Properties" on the desired container, go to the "Security" tab and click on : Advanced.

As you can see, many permissions already exist by default.
To add a permission, click on : Add.

To begin with, the "principal" to whom you want to allow or deny specific rights.

Indicate the name of the user or group that will receive the permissions (of type : allow or deny).

For the permission's type, you have the choice between :

  • allow
  • deny

A set of permissions can be applied to :

  • this object and all descendant objects
  • all descendant objects
  • descendant objects of the desired type : group, computer, site, user, ...

Here, you will find a long list of permissions.

But also a list of properties a little further down.

At the bottom, you can choose to apply these permissions only to objects and/or containers that are part of that container.

As you have manually chosen the permissions, the access displayed will be : Special.

The previously selected principal will also be displayed in the "Security" tab.

Share this tutorial

Partager
Tweet

To see also

  • Windows Server - AD DS - How Active Directory replication works

    Windows Server 4/16/2021

    Windows Server - AD DS - How Active Directory replication works

  • Windows Server - AD DS - Overview of Active Directory functional levels

    Windows Server 4/30/2021

    Windows Server - AD DS - Overview of Active Directory functional levels

  • Windows Server - AD DS - The basics of Active Directory

    Windows Server 4/3/2021

    Windows Server - AD DS - The basics of Active Directory

  • WS 2016 - AD DS - Add a domain controller to an existing AD domain

    Windows Server 5/21/2021

    WS 2016 - AD DS - Add a domain controller to an existing AD domain

Comments

No comment

Share your opinion

Pinned content

  • Software (System admin)
  • Linux softwares
  • Our programs
  • Terms and conditions
  • Share your opinion

Contact

  • Guest book
  • Technical support
  • Contact

® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.

Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.