AD permissions

Glenn Maxwell 12,876 Reputation points
2021-07-12T13:43:34.443+00:00

Hi All

i have a user and i need to provide him permission to create users in Active Directory and add users to Active Directory groups(security groups, mail enabled security groups and Distribution lists which are in Active Directory not from Exchange). What permissions do i need to provide on OU level also i would also like to know on the domain level. Experts guide me.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2021-07-13T03:07:35.473+00:00

    Hello @Glenn Maxwell ,

    Thank you so much for posting here.

    According to our experience, if we would like to grant the user with the permission to create user and add users to the groups, we could configure the Delegate Control. For example:

    1.Right click the OU, and then choose Delegate Control.

    114016-image.png

    2.Add the user who will be granted the permissions.

    113910-image.png

    3.Grant the permissions as shown below.

    114024-image.png

    4.Then the user logs in and opens the ADUC. He has the permissions to newly create the users and add users to the groups which is in this OU.

    114052-image.png

    113880-image.png

    Notes:

    Please kindly note that the user could only have the permission to add the users to the groups in this OU. If he tried to add user to other group which is not in this OU, there is error as shown below.

    114017-image.png

    Hope it helps. For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Anonymous
    2021-07-12T13:53:27.61+00:00

    You can follow along here to delegate control.
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc771454(v=ws.10)?redirectedfrom=MSDN

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.
    0 comments No comments

  2. Glenn Maxwell 12,876 Reputation points
    2021-07-12T14:18:24.443+00:00

    if i add the user to Account Operators group will it work

    0 comments No comments

  3. Anonymous
    2021-07-12T14:30:12.897+00:00

    Probably yes.
    https://learn.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-security-groups#account-operators

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.