Delegation of dynamic groups
IT Admin delegates group management to colleagues
With DynamicGroup Delegation Mode, you can delegate several AD group management tasks.
Let local IT coordinators manage their own dynamic security groups.
With DynamicGroup Delegation Mode, you can delegate several AD group management tasks.
Let local IT coordinators manage their own dynamic security groups.
The delegation of mode of DynamicGroup enables local OU admins
to maintain self-updating security groups by themselves.
An IT admin wants to delegate the maintenance of a few dynamic security groups in Active Directory.
Local helpdesk or IT coordinators should only see OUs they have to manage.
Example: In an international company, the central IT department wants to delegate AD group management:
– Local helpdesk Germany (1): dynamic group memberships for German sites
– Local helpdesk US (2): dynamic security groups of offices in the United States.
Both local helpdesks need to manage their groups – without being able to see or edit the rest of the AD tree.
With DynamicGroup, each helpdesk sees only the organizational units for which it is authorized.
It allows delegation based on the organizational units of the site or department.
The IT Admin gives different permissions to each local OU admin / helpdesk in the
Active Directory Users and Computers Console.
The HQ administrator keeps full control of the AD tree.
DynamicGroup in admin view allows access to AD tree and services.
The IT administrator keeps full control. He has access to:
IT administrator activates the delegation mode in DynamicGroup.
1. Go to services and activate the delegation mode
2. Add your Admin Console Group under “Console Administrator Group” and save.
With DynamicGroup Delegation Mode, the IT admin can share a part of the AD administrative work with helpdesks.
Increase security and simplify teamwork through AD group delegation.
Local helpdesk 1 in Germany can only
see and manage DE and sub-OUs.
Local helpdesk in US can only
see and manage US and sub-OUs.
Both Helpdesks can not see the “Services” tab anymore (compare with picture above).
The menu items “Services” and “Configurations” are deactivated.
Helpdesks are enabled to maintain their local groups and IT admins can concentrate on other projects ;).
Delegating AD management tasks brings relief for IT departments:
Local helpdesks take over the management of their own sites.
Local admins manage dynamic groups in their own OUs.
Save time by sharing IT admin tasks with local helpdesks.
Delegates get more visibility.
They only see what they need.
© 2025 · FirstAttribute AG.