Title: [ActiveDir] Flexible permissions to modify user objects?
Brian,
First create a security group for each type support staff. You can then
delegate the appropriate permissions over individual groups, users, or
entire OUs (e.g.: delegate control to the "HSStudentSupport" security group
This is all doable through the AD access control mechanisms and security
policies. The AD Delegation of Control Wizard is included with the W2K
distribution and can help with some of this. You might also look at third
party delegation products such as Quest ActiveRoles or FAZAM from FullArmor.
Ther