1

I know you can protect OUs from accidental deleting and you can create profiles with read only privileges, but what about letting a user have write permissions on objects like user accounts but read permissions on OUs?

suoko
  • 69

1 Answers1

0

You're talking about Delegated Permissions. Create a Security Group for each permission: Write Users and Read OUs

Use the Delegated Permissions wizard and apply those individual permissions to their respective group. Add the user to both groups.

spacenomyous
  • 1,339