I need to make Non-administrator to manage OU


hello all

i have trick , can't solve it 

have centeral dc without addtional 

, have 20 branch (i make ou each branch)

i want delegate user rach ou administer 1 ou granted on (only 1 ou)

1-  i need grant each user right remote desktop on commuters in ou granted on (it should not able remote computer in other ou).

2-  i need grant users local administrator in pcs , server in ou , , not in other ou

i make group , put use member of group , delegated each user on 1 ou full control

, use restricted group make group member of local remote desktop , local administrator group

but still not able  prevent users login computer via rdp in other ous
, users become local administrator on pcs on whole  20 ous

please need explain step step 

thanks in advance 

i make ou each branch , , link restricted group gpo @ domain level

no,you should apply restricted group policy ou level not root of domain.(you should configure different restricted gpo's ou's,mean related ou.)

this posting provided no warranties or guarantees,and confers no rights. best regards burak uğur



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file