To delegate permissions to generate Group Policy Results |
-
In the Group Policy Management Console (GPMC) console tree, click the domain or organizational unit (OU) for which you want to delegate permission to generate Group Policy Results.
-
In the results pane, click the Delegation tab.
-
In the Permissions drop-down list, select Read Group Policy Results data to add a new group or user to the permissions list.
-
On the Delegation tab, click Add.
-
In the Select User, Computer, or Group dialog box, click Object Types, select the types of objects to which you want to delegate permissions for the domain, site, or OU, and then click OK.
-
Select the user or group to which permission should be delegated.
-
In the Add Group or User dialog box, in the Permissions drop-down list, select the level to which you want permissions to apply for this group or user, and then click OK.
Additional considerations
- To delegate permissions to generate Group
Policy Results for objects in a domain or OU, you must have
Modify Permissions on that domain or OU. By default, only
domain administrators and enterprise administrators have this
permission.
- You cannot delegate permission to generate
Group Policy Results for sites.
- You can also use the Delegation tab to
change or remove permissions for a group or user for Group Policy
Results data.