Default Security Concerns in Active Directory Delegation (235531)
The information in this article applies to:
- Microsoft Windows 2000 Server
This article was previously published under Q235531 SUMMARY
Windows 2000 includes a Delegation wizard to facilitate the delegation of administrative rights over containers within Active Directory.
The Delegation wizard functions by providing administrators with a set of dialog boxes designed to specify the following items:
- To whom the administrator wants to delegate authority.
- The objects to which these users should gain authority.
- The permissions the designated users have over these objects.
The Delegation wizard dynamically creates access control entries on the target container object according to the options specified in the wizard.
It is important to note that the Delegation wizard does not provide functionality to remove access control entries. If an administrator wants to reverse configuration settings created with the Delegation wizard, he or she must manually gain access to the Security Settings dialog box for the affected organizational unit and remove all added entries.
Modification Type: | Major | Last Reviewed: | 10/9/2002 |
---|
Keywords: | kbinfo KB235531 |
---|
|