The establishment and delegation of domain organizational units, as well as the realization of delegated users to create and delete users from the client
Environmental preparation:
Create a new one in the virtual machine environment:
A server host that installs the AD directory: Server2012
System: Server2012
Server2012 create a new domain: lizhilong.com
A client joining the lizhilong.com domain: Windows 10-1
System Window10
Windows10 installs AD remote tool: WindowsTH-KB2693643
WindowsTH-KB2693643 download link:
Link: https://pan.baidu.com/s/1AzedfsJtWLDCycX9_yvkyA password: fltm
I. Establishment and appointment of organizational units
1. Open the service manager of Server, click tools, and select Active Directory users and computers
2. Select lizhilong.com, right-click, select New, and then select New organizational Unit.
3. In the dialog box that pops up, write down the name of the organizational unit: production department. Build another organizational unit according to the above method: quality department
4. Select the organizational unit, production Department, and right-click in the space on the right to select the new user.
5. Create a new user with the name of supervisor and login name of lisi. Click next to set the password, which will never expire.
6. Right-click the organizational unit: production department, and select delegated control
Click next, and then select add. Add user: lisi, click next
In delegating common tasks, select the first and second, and click next to finish.
The establishment and delegation of domain organizational units have been completed above.
Verify whether the delegated user lisi can establish and delete users on the client
1. Start the client Windows 10-1 and select the user lisi to log in
2. Install AD remote service tools on the client
3. Open the start menu, select all applications, find Windows management tools, expand and select Active Directory users and computers.
4. Enter the Active Directory user and computer, select the organizational unit and create a new user in the production department: zhangsan, whose name is employee.
5. Verification: go back to Server 2012 organizational unit: production department to see if you have successfully added user zhangsan
6. Go back to Windows 10-1 to delete the user zhangsan, and then go back to Server 2012 for verification
7. The scope of the delegated user's role is limited to the current organizational unit. Try to create a new user in the quality department.
Delegated users of the above implementation can create and delete users.
To sum up, after the organizational unit is delegated, the computer where the delegated user is located needs to install AD remote tools in order to create or delete users in the organizational unit. And the delegated user can only operate within the delegated organizational unit.