What should you do?

You work as the network administrator at Domain.com. The Domain.com network consists of a
single Active Directory domain named Domain.com. Domain.com has its headquarters located in London and branch office located in Paris. All servers on the Domain.com network run Windows Server 2008 and all client computers run Windows Vista.
Domain.com has recently requested that you take on the responsibilities managing help desk calls and basic user account management. During the course of the day you receive instruction to add a new user named Rory Allen to have permission to reset passwords for all users in a specific OU. Domain.com has recently requested that you have Rory Allen not capable of making permission changes for the object within other OU’s in the domain.
What should you do?

You work as the network administrator at Domain.com. The Domain.com network consists of a
single Active Directory domain named Domain.com. Domain.com has its headquarters located in London and branch office located in Paris. All servers on the Domain.com network run Windows Server 2008 and all client computers run Windows Vista.
Domain.com has recently requested that you take on the responsibilities managing help desk calls and basic user account management. During the course of the day you receive instruction to add a new user named Rory Allen to have permission to reset passwords for all users in a specific OU. Domain.com has recently requested that you have Rory Allen not capable of making permission changes for the object within other OU’s in the domain.
What should you do?

A.
You should consider having the Rory Allen’s login account moved to an OU containing the OU.

B.
You should consider having the Delegation of Control Wizard used to assign the necessary permissions on the OU that requires being administered.

C.
You should consider having a special administration account created within the OU.

D.
You should consider having the Rory Allen login account moved into the OU which requires being administered.

Explanation:
You should then have the parent OU of the one requiring administering referred.
You should then have full permissions granted to the OU for all objects within Active Directory.
The Delegation of Control Wizard is designed to permit administrators the ability to have permissions on specific Active Directory objects organized.



Leave a Reply 1

Your email address will not be published. Required fields are marked *