PrepAway - Latest Free Exam Questions & Answers

You need to ensure that a user named User1 can link and unlink Group Policy objects (GPOs) to OU1

Your network contains an Active Directory domain named contoso.com. The domain
contains 100 user accounts that reside in an organizational unit (OU) named OU1.

You need to ensure that a user named User1 can link and unlink Group Policy objects
(GPOs) to OU1. The solution must minimize the number of permissions assigned to User1.
What should you do?

PrepAway - Latest Free Exam Questions & Answers

A.
Run the Delegation of Control Wizard on OU1.

B.
Run the Delegation of Control Wizard on the Policies container.

C.
Add User1 to the Group Policy Creator Owners group.

D.
Modify the permissions on the User1 account.

Explanation:
Delegation of Control Wizard should be used to assign the appropriate permissions to
User1.
The following are common tasks that you can select to delegate control of them: Manage
Group Policy links, Create, delete, and manage user accounts, Reset user passwords and
force password change at next logon, Read all user information, Modify the membership of a
group, Join a computer to a domain,, and many other tasks.
Permissions on the Organizational unit take precedence over user accounts permissions.
Thus by changing the permissions to the OU you can assign the appropriate permission to
the user account.
References:
http://technet.microsoft.com/en-us/library/dd145344.aspx
http://technet.microsoft.com/en-us/library/jj190062.
http://technet.microsoft.com/en-us/library/cc756952%28v=WS.10%29.aspx


Leave a Reply