4

I need to allow HR people to edit some attributes for all Active Directory users (phone numbers, address, and similar contact informations), without giving them full administrative rights. They will need the right to edit those attributes on all user accounts, regardless of the OU they're in, and this security setting should also be automatically applied to new user accounts when they are created.

How can I accomplish this?

Massimo
  • 68,714
  • 56
  • 196
  • 319

2 Answers2

8

You want to use the Delegate Permissions option in Active Directory Users and Computers. You can apply the delegation to whatever OU you want, including the domain root.

This will allow you to delegate whatever attribute-level permissions you want to whatever users/groups you define.

These permissions apply like any other and respect inheritance.

MDMarra
  • 100,183
  • 32
  • 195
  • 326
  • In our Windows Server 2008 R2 Environment, it's actually called 'Delegate Control' rather than permissions. I don't know if that changes in other versions Windows Server. – yougotiger Nov 05 '15 at 18:24
7

In ADUC, the Delegation of Control wizard will allow you to do this, using a custom task for delegation. Pick just the fields you want them to have Write access to.

mfinni
  • 35,711
  • 3
  • 50
  • 86