Task 1: Design OU Configuration for Delegation of Administration

OUs can be used to delegate the administration of objects, such as users or computers, to a designated group. Although it is possible to delegate permissions to an individual, it is a best practice to use groups because as people change in the organization, it is easier to update membership in the delegation groups than to update the permissions on objects in the directory. Delegation by means of an OU involves the following tasks:

  • Identify or create administrative groups to which rights will be delegated.

  • Place the individuals or groups to which rights will be delegated into the OU. Create the OUs to which the administrative groups will have authority.

  • Assign the object rights to ...

Get Windows Server 2008 Active Directory Domain Services now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.