AD permissions

Glenn Maxwell 10,146 Reputation points
2021-07-12T13:43:34.443+00:00

Hi All

i have a user and i need to provide him permission to create users in Active Directory and add users to Active Directory groups(security groups, mail enabled security groups and Distribution lists which are in Active Directory not from Exchange). What permissions do i need to provide on OU level also i would also like to know on the domain level. Experts guide me.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,477 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,787 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,387 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,534 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,925 questions
0 comments No comments
{count} votes

Accepted answer
  1. Hannah Xiong 6,231 Reputation points
    2021-07-13T03:07:35.473+00:00

    Hello @Glenn Maxwell ,

    Thank you so much for posting here.

    According to our experience, if we would like to grant the user with the permission to create user and add users to the groups, we could configure the Delegate Control. For example:

    1.Right click the OU, and then choose Delegate Control.

    114016-image.png

    2.Add the user who will be granted the permissions.

    113910-image.png

    3.Grant the permissions as shown below.

    114024-image.png

    4.Then the user logs in and opens the ADUC. He has the permissions to newly create the users and add users to the groups which is in this OU.

    114052-image.png

    113880-image.png

    Notes:

    Please kindly note that the user could only have the permission to add the users to the groups in this OU. If he tried to add user to other group which is not in this OU, there is error as shown below.

    114017-image.png

    Hope it helps. For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-07-12T13:53:27.61+00:00

    You can follow along here to delegate control.
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc771454(v=ws.10)?redirectedfrom=MSDN

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.
    0 comments No comments

  2. Glenn Maxwell 10,146 Reputation points
    2021-07-12T14:18:24.443+00:00

    if i add the user to Account Operators group will it work

    0 comments No comments

  3. Dave Patrick 426.1K Reputation points MVP
    2021-07-12T14:30:12.897+00:00

    Probably yes.
    https://learn.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups#account-operators

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments