Tag: groups

Active Directory Delegation: It Does Not Need to Be Hard!

One of the most important and powerful reasons that organizations consider Active Directory is the fact that delegation is built into the product. W indows NT did not have delegation, unless you want to call membership in the Account Operators group delegation! Windows Active Directory provides ​ a simple method , using the Delegate Control Wizard, to grant a group of users granular control over all or even just a subset of your Active Directory objects. For example, if you have a help desk that should have the ability to reset passwords for all users except for those in IT, you can delegate this permission to the OU that contains the non-IT employees

Going Deep With Nested Group Audits

It is one of the top three most complex areas of auditing: nested groups! You know, you find a group listed on an access control list, and you ask for the group members. You get back a list of 25 users, but you know there must be more. So you ask for not only the users, but also the groups that have membership in the original group