How to assign advanced permissions in OU?

Source: Internet
Author: User

ActiveDirectoryInOUOrganizational Unit) is very powerful and important to system administrators. The specific content is as follows.

In ActiveDirectory, you can use OU organization units) advanced security settings to implement more complex functions. For example, if you want to add the permissions to create and delete users in the "typographical Production Department" OU for the user ithanjiang, you can assign advanced permissions. The procedure is as follows:

Step 2: Open the "ActiveDirectory users and computers" window, click "View"> "advanced functions" menu commands, and switch to the advanced functions window. Right-click the "typographical Production Department" OU in the left pane, and select the "attribute" command from the shortcut menu, as shown in Figure 2008112608.

Figure 2008112608 click the "properties" command

Step 2: switch to the "Security" tab in the "typographical Production Department properties" dialog box, and click the "advanced" button, as shown in Figure 2nd.

Figure 2008112609 "typographical production department attributes" dialog box

Step 2: Open the "advanced security settings of the typographical Production Department" dialog box. In the "Permissions" tab of the dialog box, the "permission items" list lists the users and groups that have the corresponding permissions for the OU. Click Add, as shown in Figure 2008112610.

Figure 2008112610 "advanced security settings of the typographical Production Department" dialog box

Step 2: In the "Select User, computer, and group" dialog box that appears, find and select the user ithanjiang. Then, the "phase project of the typographical Production Department" dialog box is automatically displayed. On the "object" tab, select the "allow account object creation" and "allow account object deletion" check boxes in the "permission" list, and click "OK", as shown in 2008112611.

Figure 2008112611 "right phase project of typographical Production Department" dialog box

Step 2: return to the "advanced security settings of the typographical Production Department" dialog box and click "OK. In the returned "typographical Production Department properties" dialog box, click "OK" again to make the settings take effect.

After such setup, the user ithanjiang has the permission to create and delete the user account in the "typographical Production Department" OU. It is not difficult to see that advanced permission assignment can achieve flexible permission assignment operations.

It is hoped that the method of advanced permission assignment in the OU of ActiveDirectory described in this article will be helpful to readers. More information about ActiveDirectory remains to be explored and learned by readers.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.