active directory -grant permission to undelete user only move and create

jihad majed 310 Reputation points
2024-03-27T08:46:42.31+00:00

I try to give user permission in an active directory to create users and move between them, but do not delete them. When I delegate control to some group, I do not have the option to undelete users.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,858 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marcin Policht 10,675 Reputation points MVP
    2024-03-27T11:13:56.4633333+00:00

    Use Delegation of Control Wizard. This can be VERY granular. More at https://learn.microsoft.com/en-us/answers/questions/973272/delegate-help-desk-users-permission-to-move-users


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

  2. Thameur-BOURBITA 32,511 Reputation points
    2024-03-27T11:30:26.76+00:00

    Hi @jihad majed

    There is no undelete permission but you can select delete permission and choose deny.

    In target OU , go to security Tab then click on advanced to be able to add or edit custom permission:

    User's image


    Please don't forget to accept helpful answer