Article ID: 250522 - Last Review: November 1, 2006 - Revision: 4.1 Adding Users to the Directory Administrators List in Microsoft Metadirectory ServicesThis article was previously published under Q250522 On This PageSUMMARY
Adding users to the Directory Administrators List enables you to identify modifications made in the logs by specific administrators user names. Without adding users to the list, any user who logs on as administrator (provided they know the correct password) can make modifications. With this scenario there is no way of identifying exactly who made the changes. This article describes how to add users to the Directory Administrators List object.
MORE INFORMATION
When you add users to the Directory Administrator list or other list objects, you should only add the user's alias, not the user object itself. The reason for this is that if you add the alias itself, it resides only under the the list object and nowhere else in the directory. If someone were to delete the list object, then this child object would also be removed.
Viewing the List of Users Added to the Directory Administrators List
Adding an Alias for a User to the Directory Administrators List
Setting Security for the Directory Administrators List MembersAllowing Members of the Directory Administrators List Read AccessWithout setting the read access to the application node, the members of the Directory Administrators List will not be able to view the directory tree. However, by default the Directory Administrator List members will be able to search and find objects in the directory. The directory tree will be displayed while viewing the object found. Note that some objects will be modifiable, and others will not.
Allowing Members of the Directory Administrators List Members to Modify the Application NodeThe same basic steps can be used for other objects that have explicit Access Controls set:
| Article Translations
|
Back to the top
