AD Computer Move Only Permissions Not Working

TJ Cooper 26 Reputation points
2023-08-16T07:47:03.8166667+00:00

I have set permissions for a security group to create/delete computer objects in an OU and set "write all properties" (to troubleshoot) and I cannot move the computer of an OU. I get an "access denied" error. I have verified create/delete is set as is write name, Name, and DistinguishedName. That is all that is required as per what I have found online.

Write All Properties is set to "Descendent Computer Objects"

Create/Delete computer objects is set to "This object and all descent objects"

Any ideas? What am I missing

Windows for business Windows Client for IT Pros Directory services Active Directory
{count} votes

1 answer

Sort by: Most helpful
  1. Gary Reynolds 9,621 Reputation points
    2023-08-16T09:56:09.1466667+00:00

    Hi,

    Have a look at this answer, make sure you have set the permissions on both the source and destination OUs - https://learn.microsoft.com/en-us/answers/questions/973272/delegate-help-desk-users-permission-to-move-users?comment=answer-975344&page=1#comment-1349105

    Have a look at this article which will help identify the effective permissions for both the OUs and computer objects - https://nettools.net/how-to-find-active-directory-effective-rights/

    I would also check that you have unchecked the accidental deletion options from the OU.

    User's image

    Gary,


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.