In the wrong.
Active directory security groups.
The technology is that when a user logs on to a computer the machine.
Nearly every business from large sized companies to mid sized businesses on a more local scale must contend with the fact many independent agents have access to company accounts passwords data and servers.
What are active directory security groups.
There are a number of different ways to determine which groups a user belongs to.
First you can take the gui approach.
This simplifies administration by allowing you to set permissions once on multiple.
I was under the impression only helpdesk staff had rights to active directory to reset passwords and unlock accounts.
There where multiple security groups that had delegated permissions to active directory.
Nobody wants to worry about the security of their company accounts.
Active directory security groups and ad distribution groups are different things.
You can also control who receives group policy settings.
You can use these predefined groups to help control access to shared resources and to delegate specific domain wide administrative roles.
There was a group called helpdesk another group is support and one more called ad modify.
Default groups such as the domain admins group are security groups that are created automatically when you create an active directory domain.
In active directory the layout follows a tier structure comprising domains trees and forests.
In microsoft active directory when you create a new group you must select a group type the two group types security and distribution are described below.
For example you can use security groups to assign permissions to shared resources and active directory distribution groups to create e mail distribution lists in an exchange environment.
Managing active directory security group permissions.
Go to active directory users and computers.
A tree is a collection of domains and a forest is a collection of trees.