Modifying Permissions

The default permission structure of Active Directory is a great start to a secure network. However, day-to-day maintenance of the enterprise requires modifying permissions by creating and deleting groups, adding and subtracting members from groups, and adding and subtracting permissions from objects. This section looks at some examples of modifying permissions.

Let's first look at modifying permissions by using the Security tab of the Properties page of the object in the Active Directory Users and Computers MMC Snap-in. This allows a very granular approach to maintaining levels of privilege. Then, you will use a new tool in the Active Directory—the Delegation of Control Wizard—to allow en masse granting of permissions to ...

Get Special Edition Using Microsoft Active Directory now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.