This feature is used for giving rights to a User for performing some tasks behalf of you. Ex : Resetting passwords for a Group.
The Delegation Wizard can't provide everything, so you'll have to also use some additional groups to provide some more permissions to User.
There are 5 Builtin Groups are available in AD and they are
1) Administrators - 1) Create, delete, and manage user and group accounts, 2) Read all user information 3) Reset password for user accounts 4) Share Directories 5) Create, delete and manage Printers 6) Backup files and directories 7) Restore files and directories 8) Log on locally to the server 9) Shutdown the system
2) Account operator - 1) Create, delete, and manage user and group accounts, 2) Read all user information 3) Reset password for user accounts 4) Log on locally to the server 5) Shutdown the system
3) Backup Operators - 1) Backup files and directories 2) Restore files and directories 3) Log on locally to the server 4) Shutdown the system
4) Print Operators - 1) Create, delete and manage Printers 2) Log on locally to the server 3) Shutdown the system
5) Server Operators- 1) Read all user information 2) Share Directories 3) Create, delete and manage Printers 4) Backup files and directories 5) Restore files and directories 6) Log on locally to the server 7) Shutdown the system
Now for Delegation follow the steps given below:
1) Open AD users and computers.
2) Select Users group Ex : NYUsers
3) Right click >Delegate control > Next >Add >type the Username Ex : Chandu> Next > From the options select the task which you want to give to user >Next.
4) Now go to Account operations and properties > In the members of tab > Add the user > ok.
If you want chandu to control users without using Remote desktop, you can use RSAT feature (Remote server administratration Tool), you need to download this tool from MICROSOFT website and install it on client computer.
Now to Program and features to Turn on the Remote Server Administration Tools (Select Role Administration Tools, AD Domain Services tools, File Services tools) OK
Now Open MMC from start menu >File > Add and remove snap in > Add the AD users and computers option >Save the console on desktop as Users and computers as shortcut.
The Delegation Wizard can't provide everything, so you'll have to also use some additional groups to provide some more permissions to User.
There are 5 Builtin Groups are available in AD and they are
1) Administrators - 1) Create, delete, and manage user and group accounts, 2) Read all user information 3) Reset password for user accounts 4) Share Directories 5) Create, delete and manage Printers 6) Backup files and directories 7) Restore files and directories 8) Log on locally to the server 9) Shutdown the system
2) Account operator - 1) Create, delete, and manage user and group accounts, 2) Read all user information 3) Reset password for user accounts 4) Log on locally to the server 5) Shutdown the system
3) Backup Operators - 1) Backup files and directories 2) Restore files and directories 3) Log on locally to the server 4) Shutdown the system
4) Print Operators - 1) Create, delete and manage Printers 2) Log on locally to the server 3) Shutdown the system
5) Server Operators- 1) Read all user information 2) Share Directories 3) Create, delete and manage Printers 4) Backup files and directories 5) Restore files and directories 6) Log on locally to the server 7) Shutdown the system
Now for Delegation follow the steps given below:
1) Open AD users and computers.
2) Select Users group Ex : NYUsers
3) Right click >Delegate control > Next >Add >type the Username Ex : Chandu> Next > From the options select the task which you want to give to user >Next.
4) Now go to Account operations and properties > In the members of tab > Add the user > ok.
If you want chandu to control users without using Remote desktop, you can use RSAT feature (Remote server administratration Tool), you need to download this tool from MICROSOFT website and install it on client computer.
Now to Program and features to Turn on the Remote Server Administration Tools (Select Role Administration Tools, AD Domain Services tools, File Services tools) OK
Now Open MMC from start menu >File > Add and remove snap in > Add the AD users and computers option >Save the console on desktop as Users and computers as shortcut.
No comments:
Post a Comment