Usually you would modify the ACL of the OU the object is in, for delegating permissions.
You can go down to the computer object level though, for joining to the domain for example. Or allowing a service account to update certain attributes on specific objects. ________________________________ From: [email protected] [[email protected]] on behalf of Matthew Topper [[email protected]] Sent: Tuesday, May 26, 2015 9:49 AM To: [email protected] Subject: [adgpo] Security Tab on Computer Objects I’m not trying to accomplish anything specific, but I thought I’d ask this out of curiosity: Under what circumstances would you need to modify the ACL of a computer object? Is it any different for domain controllers? Matthew Topper
