Delegated permissions for removing MSMQ sub object in AD

Ben Wosjke 136 Reputation points
2022-10-18T23:19:43.267+00:00

Hi all,
i need to remove the msmq sub-object in AD from computer accounts on a recurring basis.

Specifically i am referring the the MSMQ container that gets created at CN=MSMQ,CN=ServerName,OU=OUName,DC=Company,DC=Com when enabling AD integration for MSMQ within windows.

As an admin, i (or any of the other admins) can do this - but given we want to script this ability using a service account - we are trying to lock down the permissions for this service account to that specific purpose.

Now,. before you say it, I have delegated control (and verified the delegated permissions) with the following settings

251743-image.png

and (just incase it was somehow different)

251762-image.png

and neither of these allow the service account to delete the MSMQ container.
i dont want to allocate full control to the service account over these OU's.... and am looking for assistance in what delegation allows the object to be removed.

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.