N
N
Nat Pch.2020-04-21 10:26:11
Active Directory
Nat Pch., 2020-04-21 10:26:11

Can users be added to a group outside of the managed OU?

Hello!

There is such a structure.
5e9e9b1563a8f320847622.png

1) AS Administrator Petrov 0 (red) creates and appoints the rest of Petrov 1-6 "OU Administrators", delegates to them the rights to manage ONLY his OU.
2) Each Petrov 1-6 creates his own Sidorov 1-6.

Question: Can Petrovs 1-6 include their Sidorovs in the "Users" group from the User Personnel container?
Or does it contradict the condition "manage ONLY your OU" and means that in order for Sidorovs 1-6 to become members of the "Users" group, you need to create in each OU the "Users-1 (2, 3, 4, 5, 6)" groups nested in general group Users?

upd:
There is also an idea to create an "area" attribute for accounts that is unique for each OU. And arrange so that Petrovs 1-6 have rights to the Users group, but can only change those whose "area" attribute values ​​match theirs.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
M
mumische, 2020-04-24
@mumische

May be enabled if the appropriate permissions are granted to the Users group.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question