2 Questions re: Delegation of Control in Active Directory

2 Questions re: Delegation of Control in Active Directory

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
2 Questions re: Delegation of Control in Active Directory shanediaz 12-19-2006
Posted by =?Utf-8?B?c2hhbmVkaWF6?= on December 19, 2006, 4:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I'm trying to set some permissions for a user on a particular OU in Active
Directory. Basically there are some general fields for user accounts (such
as Department, Display Name, etc.) that I want this particular user to have
write access to. So far I've had good luck, with 2 exceptions, hopefully
someone can give me some guidance here...

1) There are 2 Active Directory Properties ("mail" aka E-mail field on
General tab, and "physicalDeliveryOfficeName" aka Office field on General
tab) that do not appear when I right click the OU, go to Properties\Security
tab\Advanced and try to assign either Read or Write access. Is the absence
of these two properties due to the fact that I have "Apply onto:" set at User
objects? If so, what do I need to set "Apply onto:" to in order to see these
two attributes?

2) I want to give write access to the Title field (on the Organization
tab). I assigned this particular user Write Title access under Apply onto:
User objects, however I still can't write to that particular field. All
other fields that I assigned write access to allow me to write without any
problem. Does this Title field have some other attribute name that is less
obvious than Title?

Any help provided will be greatly appreciated. Thanks in advance!

-Shane Diaz

Posted by Joe Richards [MVP] on December 21, 2006, 8:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
1. Look at http://support.microsoft.com/kb/296490

2. This issue is probably due to display specifiers. In ADUC, the item
that says title is actually the attribute personalTitle. The attribute
title is listed as Job Title.

If you want to get involved with perms, I generally recommend going into
ADSIEDIT or better, the Security Descriptor Dialog in the latest version
of LDP (which is available in ADAM R2 and ADAM SP1) as they don't muck
with the naming or what is displayed. ADUC is for light work IMO.

joe



--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


shanediaz wrote:
> Hello,
>
> I'm trying to set some permissions for a user on a particular OU in Active
> Directory. Basically there are some general fields for user accounts (such
> as Department, Display Name, etc.) that I want this particular user to have
> write access to. So far I've had good luck, with 2 exceptions, hopefully
> someone can give me some guidance here...
>
> 1) There are 2 Active Directory Properties ("mail" aka E-mail field on
> General tab, and "physicalDeliveryOfficeName" aka Office field on General
> tab) that do not appear when I right click the OU, go to Properties\Security
> tab\Advanced and try to assign either Read or Write access. Is the absence
> of these two properties due to the fact that I have "Apply onto:" set at User
> objects? If so, what do I need to set "Apply onto:" to in order to see these
> two attributes?
>
> 2) I want to give write access to the Title field (on the Organization
> tab). I assigned this particular user Write Title access under Apply onto:
> User objects, however I still can't write to that particular field. All
> other fields that I assigned write access to allow me to write without any
> problem. Does this Title field have some other attribute name that is less
> obvious than Title?
>
> Any help provided will be greatly appreciated. Thanks in advance!
>
> -Shane Diaz

Posted by =?Utf-8?B?c2hhbmVkaWF6?= on December 26, 2006, 8:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Joe,

Thanks very much for the response! That is a great knowledge base article
and the information on Security Descriptor Dialog is good to know also. I
believe this should resolve my issue. I really appreciate it!

-Shane

"Joe Richards [MVP]" wrote:

> 1. Look at http://support.microsoft.com/kb/296490
>
> 2. This issue is probably due to display specifiers. In ADUC, the item
> that says title is actually the attribute personalTitle. The attribute
> title is listed as Job Title.
>
> If you want to get involved with perms, I generally recommend going into
> ADSIEDIT or better, the Security Descriptor Dialog in the latest version
> of LDP (which is available in ADAM R2 and ADAM SP1) as they don't muck
> with the naming or what is displayed. ADUC is for light work IMO.
>
> joe
>
>
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> Author of O'Reilly Active Directory Third Edition
> www.joeware.net
>
>
> ---O'Reilly Active Directory Third Edition now available---
>
> http://www.joeware.net/win/ad3e.htm
>
>
> shanediaz wrote:
> > Hello,
> >
> > I'm trying to set some permissions for a user on a particular OU in Active
> > Directory. Basically there are some general fields for user accounts (such
> > as Department, Display Name, etc.) that I want this particular user to have
> > write access to. So far I've had good luck, with 2 exceptions, hopefully
> > someone can give me some guidance here...
> >
> > 1) There are 2 Active Directory Properties ("mail" aka E-mail field on
> > General tab, and "physicalDeliveryOfficeName" aka Office field on General
> > tab) that do not appear when I right click the OU, go to Properties\Security
> > tab\Advanced and try to assign either Read or Write access. Is the absence
> > of these two properties due to the fact that I have "Apply onto:" set at
User
> > objects? If so, what do I need to set "Apply onto:" to in order to see
these
> > two attributes?
> >
> > 2) I want to give write access to the Title field (on the Organization
> > tab). I assigned this particular user Write Title access under Apply onto:
> > User objects, however I still can't write to that particular field. All
> > other fields that I assigned write access to allow me to write without any
> > problem. Does this Title field have some other attribute name that is less
> > obvious than Title?
> >
> > Any help provided will be greatly appreciated. Thanks in advance!
> >
> > -Shane Diaz
>

Similar ThreadsPosted
active directory August 24, 2005, 6:52 pm
Active Directory and DMZ February 11, 2008, 10:12 am
Need help on Active directory server August 12, 2005, 6:29 am
Active Directory and SSL Certificates January 11, 2006, 5:08 pm
dates in active directory February 20, 2008, 6:04 pm
Using IPSec with Active Directory authetication September 5, 2005, 2:52 am
IIS 6 w/ NT 4.0 and Active Directory Domain Accounts October 11, 2005, 1:16 pm
User Rights In Active Directory January 11, 2006, 12:50 pm
Active Directory Authentication over Firewalls January 31, 2006, 1:42 am
Active Directory Admin privileges April 28, 2006, 8:59 am

The site map in XML format XML site map

Contact Us | Privacy Policy