I have a very large AD structure for our domain and would like to delegate GPO creation to other members of my staff without making them domain administrators. Do they need special rights or privileges?
There are two ways to allocate non-administrative accounts the ability to create GPOs. They are:
- Make them a member of the Group Policy Creator Owners Group in AD Users and Computers
- Grant them the right within the Group Policy Objects node on the Delegation tab. Anyone in this list can do so.
The GPanswers.com forum is closed now (thanks, spammers!)
But we encourage you to join us at LinkedIn in the “GPO Stuff” group.
Jeremy is regular there, and there is a reasonable system to prevent junk posts.
In all, we think it’s the right place to go for Group Policy-specific questions.
It’s a private group, but just JOIN it, and the owner should approve your request.
See you there !
-Jeremy Moskowitz, Group Policy MVP