Creating your users
As seen below create new user with an adm prefix.I’ve created an OU called Domain_Administration and created all my adm users and groups in here.
Creating the groups
This step is pretty self explanatory. Create your groups that you have previously defined and add your users to the relevant group.Defining the rights for the Level 1 Support
This gives them the ability to- Change passwords
- reset password
- unlock users
- read all the attributes of an AD user
- Open Active Directory Users and Computers (ADUC)
- Enable Advanced features or you wont see the security tab mentioned in the steps to come
- Navigate to your users OU that support level 1 will manage,Right Click and Click Properties then click the Security tab
- Click Advanced
- Click Add
- Specify your group then click OK
- On the Object Tab select This object and all descendant objects
- Click Allow for:
- Read All properties
- On the drop down select Descendant User Objects and Allow the following:
- Change Password
- Reset Password
- On the drop down select Descendant User Objects and Allow the following:
Next we use a slightly different method to delegate the Level 2 Desktop Engineers permissions
0 comments :
Post a Comment