active directory -grant permission to undelete user only move and create

jihad majed 520 Reputation points
2024-03-27T08:46:42.31+00:00

I try to give user permission in an active directory to create users and move between them, but do not delete them. When I delegate control to some group, I do not have the option to undelete users.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

Answer accepted by question author
  1. Thameur-BOURBITA 36,506 Reputation points Moderator
    2024-03-27T11:30:26.76+00:00

    Hi @jihad majed

    There is no undelete permission but you can select delete permission and choose deny.

    In target OU , go to security Tab then click on advanced to be able to add or edit custom permission:

    User's image


    Please don't forget to accept helpful answer


1 additional answer

Sort by: Most helpful
  1. Marcin Policht 77,665 Reputation points MVP Volunteer Moderator
    2024-03-27T11:13:56.4633333+00:00

    Use Delegation of Control Wizard. This can be VERY granular. More at https://learn.microsoft.com/en-us/answers/questions/973272/delegate-help-desk-users-permission-to-move-users


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.