Administrative Delegation in Active Directory
Delegation of administration is a powerful capability that enables organizations to efficiently and securely distribute administrative responsibilities for various aspects of IT management amongst various IT groups, thereby reducing the number of users that need to possess administrative access in Active Directory. Delegation of administration is made possible by Active Directory's powerful security model, which lets organizations precisely delegate administrative responsibilities amongst various IT groups.
Administrative delegation is implemented by granting a security principal (e.g. a group) specific permissions that govern the enactment of the administrative task being delegated, in the ACLs of Active Directory objects that comprise the delegation scope.
The following is a list of the Top-50 most common administrative delegations in Active Directory -
| Category . |
Administrative Task . |
How to Delegate (i.e. what security permissions to grant in Active Directory ACLs) . |
User Account Management |
|
Allow Create Child User (bf967aba-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Delete Child User (bf967aba-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Extended Right Reset Password (00299570-246d-11d0-a768-00aa006e0529) Applies to: User objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property Lockout Time (28630ebf-41d5-11d1-a9c1-0000f80367c1) Applies to: User objects Inheritable Allow Write Property Account Expires (bf967915-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property sAMAccountName (3e0abfd0-126a-11d0-a060-00aa006c33ed) Applies to: User objects Inheritable Allow Write Property Logon Hours (bf9679ab-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property User Workstations (bf9679d7-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property Script Path (bf9679a8-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property Profile Path (bf967a05-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property Alt Security Identities (00fbf30c-91fe-11d1-aebc-0000f80367c1) Applies to: User objects Inheritable Allow Write Property Given Name (f0f8ff8e-1191-11d0-a060-00aa006c33ed) Applies to: User objects Inheritable Allow Write Property Surname (bf967a41-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property Title (bf967a55-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: User objects Inheritable Allow Modify Permissions Applies to: User objects Inheritable |
Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page. | ||
Computer Account Management |
|
Allow Create Child Computer (bf967a86-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Delete Child Computer (bf967a86-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Extended Right Reset Password (00299570-246d-11d0-a768-00aa006e0529) Applies to: Computer objects Inheritable Allow Write Property User Account Control (bf967a68-0de6-11d0-a285-00aa003049e2) Applies to: Computer objects Inheritable Allow Write Property sAMAccountName (3e0abfd0-126a-11d0-a060-00aa006c33ed) Applies to: Computer objects Inheritable Allow Validated Write to DNS Host Name (72e39547-7b18-11d1-adef-00c04fd8d5cd) Applies to: Computer objects Inheritable Allow Write Property Machine Role (bf9679b2-0de6-11d0-a285-00aa003049e2) Applies to: Computer objects Inheritable Allow Validated Write to Service Principal Name (f3a64788-5306-11d1-a9c5-0000f80367c1) Applies to: Computer objects Inheritable Allow Write Property Alt Security Identities (00fbf30c-91fe-11d1-aebc-0000f80367c1) Applies to: Computer objects Inheritable Allow Modify Permissions Applies to: Computer objects Inheritable |
Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page. | ||
Security Group Management |
|
Allow Create Child Group (bf967a9c-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Delete Child Group (bf967a9c-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Write Property Member (bf9679c0-0de6-11d0-a285-00aa003049e2) Applies to: Group objects Inheritable Allow Validated Write Add/Remove Self as Member (bf9679c0-0de6-11d0-a285-00aa003049e2) Applies to: Group objects Inheritable Allow Write Property Group Type (9a9a021e-4a5b-11d1-a9c3-0000f80367c1) Applies to: Group objects Inheritable Allow Write Property Group Type (9a9a021e-4a5b-11d1-a9c3-0000f80367c1) Applies to: Group objects Inheritable Allow Write Property Email Addresses (bf967961-0de6-11d0-a285-00aa003049e2) Applies to: Group objects Inheritable Allow Write Property Description (bf967950-0de6-11d0-a285-00aa003049e2) Applies to: Group objects Inheritable Allow Write Property Managed By (0296c120-40da-11d1-a9c0-0000f80367c1) Applies to: Group objects Inheritable Allow Modify Permissions Applies to: Group objects Inheritable |
Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page. | ||
OU & Container Management |
|
Allow Create Child Organizational Unit (bf967aa5-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Delete Child Organizational Unit (bf967aa5-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Create Child Container (bf967a8b-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable Allow Delete Child Container (bf967a8b-0de6-11d0-a285-00aa003049e2) Applies to: This object and all child objects Inheritable See Note 4 below See Note 4 below Allow Extended Right Generate Resultant Set of Policy (Logging) (b7b1b3de-ab09-4242-9e30-9980e5d322f7) Applies to: OUs Inheritable Allow Extended Right Generate Resultant Set of Policy (Planning) (b7b1b3dd-ab09-4242-9e30-9980e5d322f7) Applies to: OUs Inheritable Allow Modify Permissions Applies to: Organizational Unit objects (i.e. OUs) Inheritable Allow Modify Permissions Applies to: Container objects Inheritable |
Note - To identify who is actually delegated the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions. For details, please note titled Important at the bottom of this page. | ||
-
Notes -
ACEs specified above need not always be Inheritable in nature. Inheritable ACEs merely make it easier to manage administrative delegations. Should there be a need to implement one-off delegations, ACEs can also alternatively be Explicit in nature (, in which case the Applies To field is empty.)
When using Inheritable ACEs, the access specified in the How to Delegate column above is to be specified in the ACLs of organizational units (OUs) that constitute the scope of the intended administrative delegation.
In the Applies To field specifications above, it is understood that the word Descendant may be prepended in all object-specific specifications e.g. "Applies to: User objects" should be read as "Applies to: Descendant User objects".
This delegation requires two ACEs: Allow Write Property GP Link (f30e3bbe-9ff0-11d1-b603-0000f80367c1) Applies to: Organizational Unit objects Inheritable + Allow Write Property GP Options (f30e3bbf-9ff0-11d1-b603-0000f80367c1) Applies to: Organizational Unit objects Inheritable
Important - Delegating administrative access in Active Directory is straightforward, easy and can be done with precision. However, assessing who is delegated what access in Active Directory is not quite as easy or straightforward, because there invariably also exist other security permissions in the ACLs of the same Active Directory objects, and they could influence the resulting access on these objects, and as a result (intentionally or otherwise) end up either denying access to delegated personnel and/or granting similar access to others as well, which is why assessing, auditing and/or verifying administrative delegations in Active Directory requires the calculation of Active Directory Effective Permissions on all relevant objects in the scope of delegation.