Active Directory has great support for fine-grained permissions, and Microsoft intent all along was for you to be able to dole out just the permissions people needed over specific portions of the directory. Delegation was intended to be a way for certain tasks to be taken off of IT's back, and put into the hands of people throughout the organization. Keeping directory attributes updated, unlocking accounts, resetting password, whatever you need to delegate can be done. The Delegation of Control (DoC) Wizard makes it pretty easy to set up, offering pre-packaged sets of permissions that you can drop onto an organizational unit (OU).
The problem is in maintaining that delegation over time. The native Active Directory tools don't provide any way of seeing who has been delegated what, apart from the native, one-object-at-a-time permissions dialog.
In this whitepaper, we will discuss the challenges of managing delegation with native tools and how you can end the delegation nightmare with Active Administrator from ScriptLogic.
DatacenterDynamics is a brand of DCD Group, a global B2B media and publishing company that develops products to help senior professionals in the world's most ICT dependent organizations make risk-based infrastructure and capacity decisions.
Our portfolio of live events, online and print publishing, business intelligence and professional development brands are centred on the complexities of technology convergence. Operating in 42 different countries, we have developed a unique global knowledge and networking platform, which is trusted by over 30,000 ICT, engineering and technology professionals.
Data Centre Dynamics Ltd.
102-108 Clifton Street
London EC2A 4HW