Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > move objects between group policies rights

Reply
Thread Tools Display Modes

move objects between group policies rights

 
 
2010
Guest
Posts: n/a

 
      11-23-2009
I would like to be able to allow user to manage group policy but not active
directory. However I need the abiltiy for that user to be able to move users
and computer in and out of different organizational groups to receive
differenet GP settings. Is there a way to do this and limit users role in
active directory to only allow objects to be moved in and out of GPOs? It is
fine to have full control of Group Policy.
 
Reply With Quote
 
 
 
 
Florian Frommherz [MVP]
Guest
Posts: n/a

 
      11-23-2009

Howdie!

2010 wrote:
> I would like to be able to allow user to manage group policy but not active
> directory. However I need the abiltiy for that user to be able to move users
> and computer in and out of different organizational groups to receive
> differenet GP settings. Is there a way to do this and limit users role in
> active directory to only allow objects to be moved in and out of GPOs? It is
> fine to have full control of Group Policy.


That's two different things:
(1) move users from OU to OU
(2) manage Group Policy

Is it necessary that you grant that user both permissions?

For (1), you need to use the "Delegation of Control" wizard in Active
Directory users and computers - or any other tool that is capable of
altering AD ACLs. To move objects, a user needs both "create" permission
in the new OU and "Delete object" permission in the old OU. Joe has an
explaination of this: http://blog.joeware.net/2005/07/17/48/

(2) This is a little more complicated as users need both access to the
GPC (the AD parts) and the GPT (the SYSVOL parts) of the policy. You can
grant pretty much all permission in GPMC.

Cheers,
Florian
 
Reply With Quote
 
2010
Guest
Posts: n/a

 
      11-23-2009
Thanks. I am going to try to implement this today.

For the second part though, wouldn't adding the user to the "Group Policy
Creator Owners Group" give them these rights on the GPC and\or GPT parts of
Group Policy?

"Florian Frommherz [MVP]" wrote:

> Howdie!
>
> 2010 wrote:
> > I would like to be able to allow user to manage group policy but not active
> > directory. However I need the abiltiy for that user to be able to move users
> > and computer in and out of different organizational groups to receive
> > differenet GP settings. Is there a way to do this and limit users role in
> > active directory to only allow objects to be moved in and out of GPOs? It is
> > fine to have full control of Group Policy.

>
> That's two different things:
> (1) move users from OU to OU
> (2) manage Group Policy
>
> Is it necessary that you grant that user both permissions?
>
> For (1), you need to use the "Delegation of Control" wizard in Active
> Directory users and computers - or any other tool that is capable of
> altering AD ACLs. To move objects, a user needs both "create" permission
> in the new OU and "Delete object" permission in the old OU. Joe has an
> explaination of this: http://blog.joeware.net/2005/07/17/48/
>
> (2) This is a little more complicated as users need both access to the
> GPC (the AD parts) and the GPT (the SYSVOL parts) of the policy. You can
> grant pretty much all permission in GPMC.
>
> Cheers,
> Florian
> .
>

 
Reply With Quote
 
Florian Frommherz [MVP]
Guest
Posts: n/a

 
      11-23-2009
Howdie!

2010 schrieb:
> Thanks. I am going to try to implement this today.
>
> For the second part though, wouldn't adding the user to the "Group Policy
> Creator Owners Group" give them these rights on the GPC and\or GPT parts of
> Group Policy?


Not sure about that. It's been a while when I last had to do that. I
remember that, back then, I had to delegate another permission to the
user - that was write/delete the OU's "gpLink" attribute which is the
attribute where the "GPO link" is stored. You may also want to look into
that.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
ANY advice you get on the Newsgroups should be tested thoroughly in your
lab.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Move \Users folder once for all Peter Meinl Windows Vista Installation 25 03-03-2010 02:37 AM
Re: Group Policies Meinolf Weber [MVP-DS] Windows Server 5 10-30-2009 05:47 AM
Group Policies and Vista - can't reset value Bear Windows Vista Administration 0 09-26-2007 05:16 PM
HELP sfc /scannow William Beard Windows Vista Performance 17 05-11-2007 04:28 AM
Moving a file that required admin rights, it does it twice! Jon Abbott Windows Vista File Management 1 06-30-2006 08:15 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59