You are an Enterprise administrator for contoso.com. The corporate network of the company consists of a single Active Directory (AD) domain. All the servers on the network run Windows Server 2008 and all client computers run Windows Vista.
The AD contains an organizational unit (OU) called EmployeesOU that contains all user accounts and a global group named HRAdmins that contains the accounts of the HR administrators?
You have been asked to plan for the delegation of administrative authority in such a way that the HR Admins are allowed to create user accounts in the EmployeesOU and change the address attributes, the telephone number attributes, and the location attributes for existing user accounts. You also need to ensure that HRAdmins are not allowed to reset the passwords for the existing user accounts.
Which of the following options would you choose to accomplish the desired goal?
A.
Run the Delegation of Control Wizard on the EmployeesOU.
B.
Create a new OU and move the HR Admins group to the new OU and then run the Delegation of Control Wizard on the new OU.
C.
Move the HRAdmins group to the Domain Controllers OU.
D.
Add the HRAdmins group to the Account Operators group.
E.
None of the above.
Explanation:
To accomplish the desired goal o accomplish the desired goal, you need to Run the Delegation of Control Wizard on the EmployeesOU. A Delegation wizard can be used to facilitate the delegation of administrative rights over containers within Active Directory. The Delegation wizard dynamically creates access control entries on the target container object according to the options specified in the wizard.
The Delegation of Control Wizard provides an additional level of granularity allowing for custom-built tasks to be assigned to specific users or groups.