How can I remove 'delete a user account' permissions from an account operator?
Continue Reading This Article
Enjoy this article as well as all of our content, including E-Guides, news, tips and more.
- To allow account operators to do everything to manage accounts except delete user accounts, you can deny account operators the "Delete all child objects" permission on the users container in Active Directory users and computers. If all user accounts do not reside in this container, you will have to make the same change to all user account containing organizational units (OUs).
- The second option is to create a custom security group and only give it the permissions over user accounts that you desire. After creating the group, use the delegation of control wizard. When you are done, add members to this group that you wish. Delegation of administrative authority to security groups may be of help.