Resolution
goal
How do I delegate the ability to synchronize BDC's in Directory and Resource Administrator?
fact
Directory and Resource Administrator 6.x
fact
Directory and Resource Administrator 7.x
fix
How do I delegate the ability to synchronize BDC's in Directory and Resource Administrator?
fact
Directory and Resource Administrator 6.x
fact
Directory and Resource Administrator 7.x
fix
To delegate the ability to synchronize BDC's in an NT domain using Directory and Resource Administrator (DRA), please perform the following steps:
In DRA 6.x versions:
- Launch the 'MMC 'interface while logged on as an Assistant Admin with, at minimum, Built-in Security Role
- Expand "ActiveView management" node
- Highlight ActiveViews and click New
- Type in a name for the ActiveView and click Finish
- Select Custom rule, in the Add Objects dialog box and click Next
- Select the Include option and click Next
- Highlight Computers and click Next
- Define the scope of the BDC's (you may specify the Include Domain Controllers with name matching option) and click Next
- Click Finish
- Click Assign Assistant Admins, in the "What would you like to do next?" dialog box
- Click Add users, select the Assistant Admin account, and click Add
- Click OK | Next
- Click Add Powers
- Expand the Computers node
- Highlight the power Synchronize Domain Controllers and select Add
- Select Next and Finish
In DRA 7.x versions:
- Launch the Delegation and Configuration console while logged on with the service account or as a DRA Administrator account
- Expand the Delegation Management node and select ActiveViews
- Click New ActiveView
- Click Next
- Click Add and select Objects that match a rule...
- Select Computers
- Define the scope of the BDC's (you may specify the Domain Controllers Matching Wildcard... option) and click OK
- Click Next
- Type in a name for the ActiveView and click Next
- Click Finish
- Click Next and Add
- Select Users...
- Type in the name of the Assistant Admin and click Find Now
- Highlight the Assistant Admin and click Add, then OK
- Click Next
- Click Add and select Powers
- Type in Synchronize Domain Controllers and click Find Now
- Highlight the power and click Add, then OK
- Click Next
- Click Next again and then Finish
Additional Information
Formerly known as NETIQKB33180