|
Lesson 3
Identifying Client and Server Default Security Settings
8-25
There are two ways to modify the default permissions that the Windows
operating sys-
tem assigns to Active Directory objects. You can use the Delegation Of
Control Wizard
in the Active Directory maintenance snap-ins for the Microsoft Management
Console
(MMC), or you can modify the permissions directly. The Delegation Of Control
Wizard
simplifies the process of delegating responsibility for a part of the Active
Directory
database to a user or group (see Figure 8-6).
f08pm06
Figure 8-6
The Delegation Of Control Wizard
The drawback of using the Delegation Of Control Wizard is that you cannot
view the
permissions you have set after you have assigned them. To do this, you must
work
with the permissions directly. By default, Windows directory service tools
such as
Active Directory Users And Computers do not provide direct access to the
permissions.
To modify this default, you select the Advanced Features option from the
console’s
View menu. Once you do this, the Properties dialog box for each Active
Directory
object displays a standard Security tab, as shown in Figure 8-7.
|