question

GlennMaxwell-2309 avatar image
0 Votes"
GlennMaxwell-2309 asked HannahXiong-MSFT edited

AD permissions

Hi All

i have a user and i need to provide him permission to create users in Active Directory and add users to Active Directory groups(security groups, mail enabled security groups and Distribution lists which are in Active Directory not from Exchange). What permissions do i need to provide on OU level also i would also like to know on the domain level. Experts guide me.

windows-active-directorywindows-server-2019windows-server-2016windows-group-policywindows-server-2012
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HannahXiong-MSFT avatar image
0 Votes"
HannahXiong-MSFT answered HannahXiong-MSFT edited

Hello @GlennMaxwell-2309,

Thank you so much for posting here.

According to our experience, if we would like to grant the user with the permission to create user and add users to the groups, we could configure the Delegate Control. For example:

1.Right click the OU, and then choose Delegate Control.

114016-image.png

2.Add the user who will be granted the permissions.

113910-image.png

3.Grant the permissions as shown below.

114024-image.png

4.Then the user logs in and opens the ADUC. He has the permissions to newly create the users and add users to the groups which is in this OU.

114052-image.png

113880-image.png

Notes:

Please kindly note that the user could only have the permission to add the users to the groups in this OU. If he tried to add user to other group which is not in this OU, there is error as shown below.

114017-image.png

Hope it helps. For any question, please feel free to contact us.

Best regards,
Hannah Xiong



image.png (14.2 KiB)
image.png (15.5 KiB)
image.png (22.6 KiB)
image.png (67.4 KiB)
image.png (41.5 KiB)
image.png (19.8 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
1 Vote"
DSPatrick answered

You can follow along here to delegate control.
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc771454(v=ws.10)?redirectedfrom=MSDN

--please don't forget to upvote and Accept as answer if the reply is helpful--



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

GlennMaxwell-2309 avatar image
0 Votes"
GlennMaxwell-2309 answered

if i add the user to Account Operators group will it work

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

Probably yes.
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups#account-operators

--please don't forget to upvote and Accept as answer if the reply is helpful--


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.