Delegate Permissions to Generate Group Policy Results

Applies To: Windows 8, Windows Server 2008 R2, Windows Server 2012

To delegate permissions to generate Group Policy Results

  1. In the Group Policy Management Console (GPMC) console tree, click the domain or organizational unit (OU) for which you want to delegate permission to generate Group Policy Results.

  2. In the results pane, click the Delegation tab.

  3. In the Permissions drop-down list, select Read Group Policy Results data to add a new group or user to the permissions list.

  4. On the Delegation tab, click Add .

  5. In the Select User, Computer, or Group dialog box, click Object Types , select the types of objects to which you want to delegate permissions for the domain, site, or OU, and then click OK .

  6. Select the user or group to which permission should be delegated.

  7. In the Add Group or User dialog box, in the Permissions drop-down list, select the level to which you want permissions to apply for this group or user, and then click OK .

Additional considerations

  • To delegate permissions to generate Group Policy Results for objects in a domain or OU, you must have Modify Permissions on that domain or OU. By default, only domain administrators and enterprise administrators have this permission.

  • You cannot delegate permission to generate Group Policy Results for sites.

  • You can also use the Delegation tab to change or remove permissions for a group or user for Group Policy Results data.

Additional references