Admin account unable to delete/edit disabled user accounts in AD

BraxJay 21 Reputation points
2020-12-17T21:34:57.863+00:00

We have a help desk admin that’s unable to delete/edit any user accounts that have been disabled. It’s all greyed out for them; removing security groups of the user doesn’t work.

What setting do we need to enable for them to do so. Our high level admins have the access, I just don’t know what adjustment needs to be made.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,453 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,326 Reputation points Microsoft Vendor
    2020-12-18T00:30:14.77+00:00

    Hi,

    To assign permissions for managing user accounts, we can consider the delegation control.
    You can try to use the delegation control to assign permission for the helpdesk user as following:
    Right click the domain name,
    49352-12183.jpg
    49353-12184.jpg
    You can assign the permission as the screenshot or you can customer the task.
    49286-12185.jpg

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2020-12-17T21:37:48.037+00:00

    Might do
    whoami /groups
    and compare the results between the two.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.