Usually you would modify the ACL of the OU the object is in, for delegating 
permissions.

You can go down to the computer object level though, for joining to the domain 
for example.

Or allowing a service account to update certain attributes on specific objects.

________________________________
From: [email protected] [[email protected]] on behalf 
of Matthew Topper [[email protected]]
Sent: Tuesday, May 26, 2015 9:49 AM
To: [email protected]
Subject: [adgpo] Security Tab on Computer Objects

I’m not trying to accomplish anything specific, but I thought I’d ask this out 
of curiosity:


Under what circumstances would you need to modify the ACL of a computer object? 
 Is it any different for domain controllers?


Matthew Topper

Reply via email to