Your network consists of one Active directory domain. The functional level of the domain is Windows
Server2008 R2. Your company has 10 departments. Each department has a department manager
and a department administrator. Some department administrators are responsible for multiple
departments. You have an organizational unit (OU) named All Users that contains all user accounts.
You need to recommend a solution to simplify the management of all users in the domain. The
solution must meet the following requirements:
Department managers must only be able to reset passwords for users in their respective
departments.
Department administrators must only be able to modify user accounts in their respective
departments.
Only the respective department administrators and managers must be able to manage the
accounts of users who are transferred to their departments from other departments.
What should you recommend?
A.
Create an OU for each department. Delegate password control for each new OU to the respective
department manager. Delegate administration of each new OU to the respective department
administrator.
B.
Create an OU for each department. When the same administrator is responsible for multiple
departments, create only one OU for those departments. Delegate password control for each new
OU to the respective department manager. Delegate administration of each new OU to the
respective department administrator.
C.
Create an OU for each department. When the same administrator is responsible for multiple
departments, create a new OU and nest the OUs of those departments into the new OU. Delegate
password control for each new OU to the respective to the respective department manager.
Delegate administration of each new OU to the respective department administrator.
D.
Create a global security group for each department. Add all the users, department managers, and
administrators from each department to the global security group. Delegate password control to the
department managers of the AllUsers OU. Delegate administration to the department administrators
of the AllUsers OU.
Explanation:
To accomplish the desired goal by using the minimum amount of administrative effort, you need to
first create an OU for each department so that each department can be managed separately You
need to then delegate the password control for each new OU to the respective department manager
so that the password control of each department can be managed by the respective department
managers. Finally, you need to delegate administration of each new OU to the respective
department administrator to ensure that the department administrators must be allowed to modify
the user accounts of only their departments.
Organizational Unit
http://en.wikipedia.org/wiki/Organizational_Unit