Administrative Delegation

Administrative Delegation in Active Directory

Delegation of administration is a powerful capability that enables organizations to efficiently and securely distribute administrative responsibilities for various aspects of IT management amongst various IT groups, thereby reducing the number of users that need to possess administrative access in Active Directory. Delegation of administration is made possible by Active Directory's powerful security model, which lets organizations precisely delegate administrative responsibilities amongst various IT groups.


Administrative delegation is implemented by granting a security principal (e.g. a group) specific permissions that govern the enactment of the administrative task being delegated, in the ACLs of Active Directory objects that comprise the delegation scope.


The following is a list of the Top-50 most common administrative delegations in Active Directory -

Category
.
Administrative Task
.
How to Delegate  (i.e. what security permissions to grant in Active Directory ACLs)
.
User Account Management
  1. Create user accounts
  2. Delete user accounts
  3. Reset the passwords of user accounts
  4. Disable/enable user accounts
  5. Unlock locked user accounts
  6. Unexpire expired user accounts
  7. Force users to change their passwords at next logon
  8. Change the logon name of user accounts
  9. Change the logon hours of user accounts
  10. Change the logon workstations of user accounts
  11. Change the logon script of user accounts
  12. Change the profile path of user accounts
  13. Change alternate security identities associated with user accounts
  14. Change the first name of user accounts
  15. Change the last name of user accounts
  16. Change the organizational title of user accounts
  17. Change whether or not user accounts are sensitive and cannot be delegated
  18. Change whether or not Kerberos pre-authentication is required for user accounts
  19. Change whether or not DES encryption types should be used for user accounts
  20. Change the security permissions protecting user accounts

Allow Create Child  User (bf967aba-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Delete Child  User (bf967aba-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Extended Right  Reset Password (00299570-246d-11d0-a768-00aa006e0529)  Applies to: User objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  Lockout Time (28630ebf-41d5-11d1-a9c1-0000f80367c1)  Applies to: User objects  Inheritable 

Allow Write Property  Account Expires (bf967915-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  sAMAccountName (3e0abfd0-126a-11d0-a060-00aa006c33ed)  Applies to: User objects  Inheritable 

Allow Write Property  Logon Hours (bf9679ab-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  User Workstations (bf9679d7-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  Script Path (bf9679a8-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  Profile Path (bf967a05-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  Alt Security Identities (00fbf30c-91fe-11d1-aebc-0000f80367c1)  Applies to: User objects  Inheritable 

Allow Write Property  Given Name (f0f8ff8e-1191-11d0-a060-00aa006c33ed)  Applies to: User objects  Inheritable 

Allow Write Property  Surname (bf967a41-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  Title (bf967a55-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: User objects  Inheritable 

Allow Modify Permissions  Applies to: User objects  Inheritable 


Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page.


Computer Account Management
  1. Create computer accounts
  2. Delete computer accounts
  3. Reset the passwords of computer accounts
  4. Disable/enable computer accounts
  5. Change the computer name of computer accounts
  6. Change the DNS name of computer accounts
  7. Change the machine role of computer accounts
  8. Change the SPN of computer accounts
  9. Change alternate security identities associated with computer accounts
  10. Change the security permissions protecting computer accounts

Allow Create Child  Computer (bf967a86-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Delete Child  Computer (bf967a86-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Extended Right  Reset Password (00299570-246d-11d0-a768-00aa006e0529)  Applies to: Computer objects  Inheritable 

Allow Write Property  User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2)  Applies to: Computer objects  Inheritable 

Allow Write Property  sAMAccountName (3e0abfd0-126a-11d0-a060-00aa006c33ed)  Applies to: Computer objects  Inheritable 

Allow Validated Write  to DNS Host Name (72e39547-7b18-11d1-adef-00c04fd8d5cd)  Applies to: Computer objects  Inheritable 

Allow Write Property  Machine Role (bf9679b2-0de6-11d0-a285-00aa003049e2)  Applies to: Computer objects  Inheritable 

Allow Validated Write  to Service Principal Name (f3a64788-5306-11d1-a9c5-0000f80367c1)  Applies to: Computer objects  Inheritable 

Allow Write Property  Alt Security Identities (00fbf30c-91fe-11d1-aebc-0000f80367c1)  Applies to: Computer objects  Inheritable 

Allow Modify Permissions  Applies to: Computer objects  Inheritable 


Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page.


Security Group Management
  1. Create security groups
  2. Delete security groups
  3. Change security group membership
  4. Add/remove oneself from a security group
  5. Change the scope of security groups
  6. Change the type of security groups
  7. Change the email-address of security groups
  8. Change the description of security groups
  9. Change the designated manager of security groups
  10. Change the security permissions protecting security groups

Allow Create Child  Group (bf967a9c-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Delete Child  Group (bf967a9c-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Write Property  Member (bf9679c0-0de6-11d0-a285-00aa003049e2)  Applies to: Group objects  Inheritable 

Allow Validated Write  Add/Remove Self as Member (bf9679c0-0de6-11d0-a285-00aa003049e2)  Applies to: Group objects  Inheritable 

Allow Write Property  Group Type (9a9a021e-4a5b-11d1-a9c3-0000f80367c1)  Applies to: Group objects  Inheritable 

Allow Write Property  Group Type (9a9a021e-4a5b-11d1-a9c3-0000f80367c1)  Applies to: Group objects  Inheritable 

Allow Write Property  Email Addresses (bf967961-0de6-11d0-a285-00aa003049e2)  Applies to: Group objects  Inheritable 

Allow Write Property  Description (bf967950-0de6-11d0-a285-00aa003049e2)  Applies to: Group objects  Inheritable 

Allow Write Property  Managed By (0296c120-40da-11d1-a9c0-0000f80367c1)  Applies to: Group objects  Inheritable 

Allow Modify Permissions  Applies to: Group objects  Inheritable 


Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page.


OU & Container Management
  1. Create organizational units
  2. Delete organizational units
  3. Create containers
  4. Delete containers
  5. Link group policies to organizational units
  6. Change precedence of group policies linked to organizational units
  7. Generate resultant set of policy for users/computers (Logging Mode)
  8. Generate resultant set of policy for users/computers (Planning Mode)
  9. Change the security permissions protecting organizational units
  10. Change the security permissions protecting containers

Allow Create Child  Organizational Unit (bf967aa5-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Delete Child  Organizational Unit (bf967aa5-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Create Child  Container (bf967a8b-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

Allow Delete Child  Container (bf967a8b-0de6-11d0-a285-00aa003049e2)  Applies to: This object and all child objects  Inheritable 

See Note 4 below

See Note 4 below

Allow Extended Right  Generate Resultant Set of Policy (Logging) (b7b1b3de-ab09-4242-9e30-9980e5d322f7)  Applies to: OUs  Inheritable 

Allow Extended Right  Generate Resultant Set of Policy (Planning) (b7b1b3dd-ab09-4242-9e30-9980e5d322f7)  Applies to: OUs  Inheritable 

Allow Modify Permissions  Applies to: Organizational Unit objects (i.e. OUs)  Inheritable 

Allow Modify Permissions  Applies to: Container objects  Inheritable 


Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page.





Important - Delegating administrative access in Active Directory is straightforward, easy and can be done with precision. However, assessing who is delegated what access in Active Directory is not quite as easy or straightforward, because there invariably also exist other security permissions in the ACLs of the same Active Directory objects, and they could influence the resulting access on these objects, and as a result (intentionally or otherwise) end up either denying access to delegated personnel and/or granting similar access to others as well, which is why assessing, auditing and/or verifying administrative delegations in Active Directory requires the calculation of Active Directory Effective Permissions on all relevant objects in the scope of delegation.