Learn AD in 15 Minutes a Week: Delegation of Authority – Assigning Object Permissions

Published: Jul 20, 2010
Updated: Nov 10, 2020
2 minute read
ServerWatch のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る



by Jason Zandri

www.2000trainers.com


Welcome to the 12th installment of Learn Active Directory Design and Administration in 15 Minutes a Week, a weekly series aimed
at current IT professionals preparing to write the new Windows Active Directory Design and Administration exams (70-219 and 70-217 respectively), as well as newcomers to the field who are trying to get a solid grasp on this new and emerging directory service from Microsoft. This
installment is going to review the Windows 2000 Active
Directory Delegation of Authority – Assigning Permissions,
which is going to specifically cover Assigning Permissions to Active
Directory Objects.

Jason Zandri’s latest article in the Learn Active Directory Design and Administration in 15 Minutes a Week series reviews the Windows 2000 Active Directory Delegation of Authority – Assigning Permissions, with a specific focus on Assigning Permissions to Active Directory Objects.


Assigning Object Permissions

By
delegating control of the day to day administration at the
organizational unit level in your domains throughout your
Windows 2000 Forest to other responsible domain members and
junior administrators, you allow for decentralized
administrative operations closer to the worker level, and you allow
for more seasoned Administrators to concentrate on
Enterprise wide services and issues.

You can use permissions to grant administrative control to a specific
user or groups of users so that they can administer a
single organizational unit or an entire hierarchy of
organizational units, depending on your needs and the detail
of delegation your Enterprise requires.

You can
allow or deny permissions for every object in Active
Directory as long as you are the owner of that object.
Permissions can be set both implicitly or explicitly, and
they can be allowed or denied and can be set as standard
permissions or as special permissions.

Advertisement

[NOTES
FROM THE FIELD] – Domain and Enterprise
Administrators have the rights to allow or deny permissions
for every object in Active Directory, in addition to any
other owners that may own the objects.

The
permissions on all Active Directory objects are stored in
that object’s DACL (Discretionary Access Control List). Each
individual permission that is set, both allow and deny, is
contained in an ACE (Access Control Entry).

[NOTES
FROM THE FIELD] – In order to view the Security tab
of an object and/or to see other advanced views in the
Active Directory Users and Computers MMC, you need to select
VIEW and then choose Advanced Features.


ServerWatch Logo

ServerWatch is a top resource on servers. Explore the latest news, reviews and guides for server administrators now.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。