![]() ![]() Increasing the number of users with full control over everything in the domain would create a huge security concern. This would provide these users with the abilities to perform those tasks but would introduce the risk for them to make unwanted or accidental changes that could result in misconfiguration or downtime. Why shouldn’t you give Domain Admin privileges to all the users you want to perform common tasks like password resets or unlocking of accounts? Delegation of permissions is necessary to help manage the ongoing operations of an organization. This removes the burden of only having AD admins being able to perform these tasks. AD permission delegation refers to the assigning of administrative controls over specified objects within the Active Directory structure to users or groups.
0 Comments
Leave a Reply. |