Active Directory: How to let a group manage another group

active-directorygroup-policywindows-server-2003

I have a group (group1) containing users.
In real life, this group is handled by two people (group1-leads).

I want group1-leads to be able to manage group1.

So I double-click on group1 navigate to the Managed By tab and change to group1-leads.

However when I click "OK", I get an error message telling me:

An object (User) with the following name cannot be found:
group1-leads… bla bla bla

How do I set a group in this field?

Best Answer

The same effect can be accomplished by setting a custom AD right. I don't have AD in front of me right now so I don't have the exact attribute needed, so please bear with me.

If you go into the Group you want to be managed, go to the Security tab and hit Advanced.

  1. Click the Add a new privilege button.
  2. Enter the group you want to manage this group
  3. In the big list, search for Group Membership, members, or something like that.
  4. Check the 'allow' box next to it.

This will allow the second group to manage the membership of the first group. This won't be reflected in the "Managed By" tab, though.