Files
Compose-Files/Backups/Miker/.trash/Delegation Delegate using DSALS.md
2026-07-20 09:23:17 -04:00

629 lines
37 KiB
Markdown
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
**Delegation-User-Attributes**
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;displayName;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;sn;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;description;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;mail;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;targetAddress;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;proxyAddresses;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute1;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute2;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute3;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute4;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute5;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute6;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute7;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute8;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute9;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute10;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute11;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute12;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute13;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute14;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;extensionAttribute15;user" /I:S
**Added 6/11/2019**
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;department;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;postalCode;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;streetAddress;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;st;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;title;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;telephoneNumber;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;mobile;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;pager;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;company;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;L;user" /I:S
**Added 9/9/2019** 
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;c;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;facsimileTelephoneNumber;user" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;physicalDeliveryOfficeName;user" /I:S
**Added 4/4/2024** **(as discussed with Marcus)**
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-User-Attributes:RPWP;altSecurityIdentities;user" /I:S
**New script to replace above…..**
**12-4-2024 Delegation "Delegation-User-Attributes"**
# Define the list of OUs
$ouList = @(
"OU=EastTexas,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=International,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NationalCapital,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NorthEast,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NorthWestCentral,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=SouthEast,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=SouthWest,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=West,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=Accounts Privileged,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=Accounts Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov"
)
# Define the commands to execute for each OU
$commands = @(
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;displayName;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;sn;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;description;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;mail;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;targetAddress;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;proxyAddresses;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;mailNickname;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;directReports;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;manager;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute1;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute10;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute11;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute12;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute13;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute14;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute15;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute16;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute17;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute18;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute19;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute2;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute20;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute3;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute4;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute5;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute6;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute7;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute8;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;DHSAttribute9;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute1;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute2;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute3;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute4;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute5;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute6;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute7;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute8;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute9;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute10;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute11;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute12;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute13;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute14;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;extensionAttribute15;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;department;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;postalCode;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;streetAddress;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;st;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;title;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;telephoneNumber;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;mobile;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;pager;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;company;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;L;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;c;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;facsimileTelephoneNumber;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;physicalDeliveryOfficeName;user" /I:S',
'DSACLS "{0}" /G "Delegation-User-Attributes:RPWP;altSecurityIdentities;user" /I:S'
)
# Loop through each OU and execute the commands
foreach ($ou in $ouList) {
foreach ($cmd in $commands) {
$commandToExecute = $cmd -f $ou
Write-Host "Executing: $commandToExecute"
Invoke-Expression $commandToExecute
}
}
**Delegation-UserPIVmaint** Added 12/5/2024
# Define the list of OUs
$ouList = @(
"OU=EastTexas,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=International,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NationalCapital,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NorthEast,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=NorthWestCentral,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=SouthEast,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=SouthWest,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=West,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=Accounts Privileged,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov",
"OU=Accounts Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov"
)
# Define the commands to execute for each OU
$commands = @(
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;account restrictions;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;pwdlastset;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;UserAccountControl;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;altSecurityIdentities;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:CA;reset password;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;DHSAttribute13;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;DHSAttribute19;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;userPrincipalName;user" /I:S',
'DSACLS "{0}" /G "Delegation-UserPIVmaint:RPWP;sAMAccountName;user" /I:S'
)
# Loop through each OU and execute the commands
foreach ($ou in $ouList) {
foreach ($cmd in $commands) {
$commandToExecute = $cmd -f $ou
Write-Host "Executing: $commandToExecute"
Invoke-Expression $commandToExecute
}
}
==View==
dsacls "DC=ad,DC=cbp,DC=dhs,DC=gov" \>ad.txt
**Added 6/10/2019**
==Service accounts servicePrincipalName delegation: Delegation-servicePrincipalName==
DSACLS "OU=Accounts Service,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-servicePrincipalName:RPWP;servicePrincipalName;user" /I:S
**Added 6/18/2025**
DSACLS "OU=SQL,OU=EIOD,OU=Accounts Group Managed System,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "DELEGATION-EIOD-SQL-SVC-ACCNT-MGMNT:RPWP;servicePrincipalName;user" /I:S
2/11/2022 SAT domain
DSACLS "OU=SQL,OU=EDMED,OU=Accounts Service,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "Delegation-servicePrincipalName-EDME-SQL:RPWP;servicePrincipalName;user" /I:S
**Added 6/18/2025**
DSACLS "OU=SQL,OU=EIOD,OU=Accounts Group Managed System,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "Delegation-servicePrincipalName-EDME-SQL:RPWP;servicePrincipalName;user" /I:S
**Added 2/26/20** (so TSD or future groups can modify extensionAttribute11 used for email automation)
DSACLS "OU=Accounts Service,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "Delegation-extensionAttribute11:RPWP;extensionAttribute11;user" /I:S
**How to grant "Write ServicePrincipalName” and “Write validated SPN” rights to the directory for service account**
Tuesday, July 31, 2018
1:45 PM
How to grant "Write ServicePrincipalName” and “Write validated SPN” rights to the directory for service account
dsacls "OU=SQL,OU=EDMED,OU=Accounts Service,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\SG-SQL-OSADMINS:RPWP;servicePrincipalName"
Only users accounts
dsacls "OU=SQL,OU=EDMED,OU=Accounts Service,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\SG-SQL-OSADMINS:RPWP;servicePrincipalName;user"
==Delegation-msRTCSIP-Attributes Deleted 12/5/24 No Longer in use==
Kellerman 10/21/19:
- Renamed original Delegation-msRTCSIP-PrimaryUserAddress to Delegation-msRTCSIP-Attributes to reflect multiple property assignments
- Added the following WR (Write) to user properties (dsacls example shows only original delegation for msRTCSIP-PrimaryUserAddress):
- msRTCSIP-ApplicationOptions
- msRTCSIP-DeploymentLocator
- msRTCSIP-Line
- msRTCSIP-OptionFlags
- msRTCSIP-OwnerUrn
- msRTCSIP-PrimaryUserAddress
- msRTCSIP-UserEnabledmsRTCSIP-UserEnabled
dsacls "OU=Accounts Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=Arizona,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=Central,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=METRO,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=NorthEast,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=NorthWest,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=SouthEast,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=SouthernCalifornia,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=SouthWest,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
dsacls "OU=International,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-msRTCSIP-Attributes:WP;msRTCSIP-PrimaryUserAddress;user"
==Delegation-UserAccessControl== ==Deleted 12/5/24 No Longer in use==
~~Usage:  Password never expires script running on tnwg01a-v0981~~
~~Account: SVC-UserAccess-CTRL~~
~~Delegates Read Write to user object “userAccountControl” parameter~~
 
==Delegation-DHSmail-OU==
**Delegate permissions to CN=Deleted Objects**
dsacls "CN=Deleted Objects,DC=ad,DC=cbp,DC=dhs,DC=gov" /takeownership
dsacls "CN=Deleted Objects,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "AD\Delegation-DHSmail-OU:LCRP"
![Delegation of Control Wizard Mive Type Indicate th...](Exported%20image%2020250808202058-0.png)
![Delegation of Control Wizard Select the permission...](Exported%20image%2020250808202059-1.png)
**Join Computer Objects / Create Computer objects /Move**
**PowerShell (tested 3/26/2020) run on both OU locations**
#$user = 'AD\Delegation-WorkstationsSpecialPurpose-BEMS-ICAD'
#$ou = 'OU=ICAD SURVEILLANCE PROCESSORS,OU=BEMSD,OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
#$ou = 'OU=ADEX,OU=WSG,OU=EDMED,OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
#$user = 'AD\Delegation-Computer-Move-Pride'
#$ou = 'OU=PRIDE-RPM,OU=LSS,OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
#$ou = 'OU=ICAD,OU=BEMSD,OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
#$user = 'AD\Deligation-Computer-Join-ICAD'
#$ou= 'OU=ICAD,OU=BEMS,OU=Servers Field,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
#$ou='OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
DSACLS $ou /R $user
DSACLS $ou /I:S /G "$($user):GR;;computer"
DSACLS $ou /I:S /G "$($user):CC;computer"
DSACLS $ou /I:S /G "$($user):CA;Reset Password;computer"
DSACLS $ou /I:S /G "$($user):CA;Change Password;computer"
DSACLS $ou /I:S /G "$($user):CA;Validated write to service principal name;computer"
DSACLS $ou /I:S /G "$($user):WP;description;computer"
DSACLS $ou /I:S /G "$($user):WP;DNS Host Name Attributes;computer"
DSACLS $ou /I:S /G "$($user):WP;pwdLastSet;computer"
DSACLS $ou /I:S /G "$($user):WP;Logon Information;computer"
DSACLS $ou /I:S /G "$($user):WP;displayName;computer"
DSACLS $ou /I:S /G "$($user):WP;sAMAccountName;computer"
DSACLS $ou /I:S /G "$($user):WP;Account Restrictions;computer"
DSACLS $ou /I:S /G "$($user):WP;servicePrincipalName;computer"
**Pride Workstations Description 4/15/2020**
dsacls "OU=PRIDE-RPM,OU=LSS,OU=Workstations Special Purpose,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\Delegation-Computer-Description-Pride:WP;description;computer"
**ICAD Privileged Accounts unlock 4/22/2020**
$user = 'AD\Delegation-AccountsPrivileged-BEMSD-ICAD-UNLOCK'
$ou = 'OU=ICAD,OU=BEMS,OU=Accounts Privileged,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
DSACLS $ou /I:S /G "$($user):CA;Reset Password;user"
**ICAD CommonUsers Accounts unlock 6/18/2020 must be run with -0 account**
$user = 'AD\Delegation-CommonUser-ICAD-Unlock'
$ou = 'OU=ICAD,OU=BEMSD,OU=Accounts Common,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov'
DSACLS $ou /I:S /G "$($user):CA;Reset Password;user"
**ICAM extensionAttribute14 rights to Server Access Groups. 8/10/2022**
SG-Delegation-Server Access-extensionAttribute14
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;==group==" /I:S
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;user" /I:S
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;==group==" /I:S
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;user" /I:S
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;==group==" /I:S
DSACLS "OU=SERVER ACCESS,OU=Groups Security,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-Server Access-extensionAttribute14:RPWP;extensionAttribute14;user" /I:S
**DMZ Delegations extensionAttribute14 and extensionAttribute13 8/30/2023**
DSACLS "OU=Groups Security,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "Delegation-SecurityGroups-extensionAttribute14:RPWP;extensionAttribute14;group" /I:S
DSACLS "OU=Groups Security,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "Delegation-SecurityGroups-extensionAttribute13:RPWP;extensionAttribute13;group" /I:S
DSACLS "OU=GROUPS-ICAM MANAGED,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "Delegation-SecurityGroups-extensionAttribute14:RPWP;extensionAttribute14;group" /I:S
DSACLS "OU=GROUPS-ICAM MANAGED,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /G "Delegation-SecurityGroups-extensionAttribute13:RPWP;extensionAttribute13;group" /I:S
**Cluster identity can update computer objects in the domain**==.== **11/8/2022**
==Reset Password==
==Validated Write to DNS Host Name==
==Validated Write to Service Principal Name==
\> From \<[https://learn.microsoft.com/en-us/answers/questions/120834/the-computer-object-associated-with-the-cluster-ne.html](https://learn.microsoft.com/en-us/answers/questions/120834/the-computer-object-associated-with-the-cluster-ne.html)\>
**SAT OU=Accounts Privileged 1/22/2025**
**SAT domain delegate rights for SailPoint team to create/enable/disable reset password on User accounts**
dsacls "OU=Accounts Privileged,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Accounts-Privileged-ICAM_MANAGED:GA;userAccountControl;user" /I:S
dsacls "OU=Accounts Privileged,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Accounts-Privileged-ICAM_MANAGED:GA;user" /I:T
$user = 'SAT\Delegation-Accounts-Privileged-ICAM_MANAGED'
$ou = 'OU=Accounts Privileged,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov'
DSACLS $ou /I:S /G "$($user):CA;Reset Password;user"
dsacls "OU=Accounts Privileged,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Accounts-Privileged-ICAM_MANAGED:CC;user" /I:S
**SAT OU=Development 1/22/2025**
**SAT domain delegate rights for SailPoint team to create/enable/disable reset password Users accounts**
dsacls "OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Development-ICAM_MANAGED:GA;user" /I:S
dsacls "OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Development-ICAM_MANAGED:GA;user" /I:T
$user = 'SAT\Delegation-Development-ICAM_MANAGED'
dsacls "OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-Development-ICAM_MANAGED:WP;userAccountControl;user" /I:S
$ou = 'OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov'
DSACLS $ou /I:S /G "$($user):CA;Reset Password;user"
**SAT OU=Development 1/23/2025**
**SAT OU Create/delete SailPoint team**
dsacls "OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-OU-Development:CC;organizationalUnit" /I:T
dsacls "OU=Development,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /G "SAT\Delegation-OU-Development:DC;organizationalUnit" /I:T
# Example:
# Cluster service Name TNWG01A-C0398$
# Cluster Nodes TNWG01A-V4273, TNWG01A-V4274
#
$ClusterServiceAccount = 'AD\TNWG01A-C0398$'
$Cmember1 = 'CN=TNWG01A-V4273,OU=RC4-DEP,OU=SQL-SERVERS,OU=SQL,OU=EDME,OU=PreProduction,DC=ad,DC=cbp,DC=dhs,DC=gov'
$Cmember2 = 'CN=TNWG01A-V4274,OU=RC4-DEP,OU=SQL-SERVERS,OU=SQL,OU=EDME,OU=PreProduction,DC=ad,DC=cbp,DC=dhs,DC=gov'
#
DSACLS $Cmember1 /I:S /G "$($ClusterServiceAccount):CA;Reset Password;computer"
DSACLS $Cmember1 /I:S /G "$($ClusterServiceAccount):CA;Validated write to service principal name;computer"
DSACLS $Cmember1 /I:S /G "$($ClusterServiceAccount):WP;DNS Host Name Attributes;computer"
DSACLS $Cmember2 /I:S /G "$($ClusterServiceAccount):CA;Reset Password;computer"
DSACLS $Cmember2 /I:S /G "$($ClusterServiceAccount):CA;Validated write to service principal name;computer"
DSACLS $Cmember2 /I:S /G "$($ClusterServiceAccount):WP;DNS Host Name Attributes;computer"
**Delegation Create/delete Organizational units** ==created 12/4/2024==
# Define the user or group and the OU path
$userOrGroup = "SAT\Delegation-OU-Development" # Replace with your user or group
$ouPath = "OU=MyTest,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" # Replace with your OU path
# Import the Active Directory module
Import-Module ActiveDirectory
# Import the required .NET namespace
Add-Type -AssemblyName System.DirectoryServices
# Get the distinguished name (DN) of the OU
$ou = Get-ADOrganizationalUnit -Identity $ouPath
# Define the ObjectType GUID for Organizational Unit
$organizationalUnitGuid = [Guid]::Parse("bf967aa5-0de6-11d0-a285-00aa003049e2")
# Define permissions for creating and deleting Organizational Units
$createPermission = [System.DirectoryServices.ActiveDirectoryRights]::CreateChild
$deletePermission = [System.DirectoryServices.ActiveDirectoryRights]::DeleteChild
# Create the access rules
$createAce = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
[System.Security.Principal.NTAccount]$userOrGroup,
$createPermission,
[System.Security.AccessControl.AccessControlType]::Allow,
$organizationalUnitGuid,
[System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
$deleteAce = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
[System.Security.Principal.NTAccount]$userOrGroup,
$deletePermission,
[System.Security.AccessControl.AccessControlType]::Allow,
$organizationalUnitGuid,
[System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
# Get the security descriptor of the parent OU
$securityDescriptor = Get-Acl -Path "AD:$($ou.DistinguishedName)"
# Add the access rules to the security descriptor
$securityDescriptor.AddAccessRule($createAce)
$securityDescriptor.AddAccessRule($deleteAce)
# Set the updated security descriptor on the parent OU
Set-ACL -Path "AD:$($ou.DistinguishedName)" -AclObject $securityDescriptor
# Verify if the permissions have been added
$updatedSecurityDescriptor = Get-Acl -Path "AD:$($ou.DistinguishedName)"
$updatedAccessRules = $updatedSecurityDescriptor.Access | Where-Object { $_.IdentityReference -eq $userOrGroup }
if ($updatedAccessRules) {
Write-Host "Permissions to create and delete Organizational Units have been successfully granted to $userOrGroup on $($ou.DistinguishedName)"
$updatedAccessRules | Format-Table -AutoSize
} else {
Write-Host "Failed to verify the delegation. Permissions may not have been applied correctly." -ForegroundColor Red
}
**Delegation Of Group Management**
![Exported image](Exported%20image%2020250808202059-2.png)
**Delegation Create/delete Groups** ==created 12/4/2024==
# Import the Active Directory module
Import-Module ActiveDirectory
# Import the required .NET namespace
Add-Type -AssemblyName System.DirectoryServices
# Define the user or group and the OU path
$userOrGroup = "SAT\Delegation-Development-GROUPS-ICAM_MANAGED" # Replace with your user or group
$ouPath = "OU=MyTest,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" # Replace with your OU path
# Get the distinguished name (DN) of the OU
$ou = Get-ADOrganizationalUnit -Identity $ouPath
# Define the ObjectType GUID for Group objects
$groupGuid = [Guid]::Parse("bf967a9c-0de6-11d0-a285-00aa003049e2")
# Define permissions for creating and deleting Group objects
$createPermission = [System.DirectoryServices.ActiveDirectoryRights]::CreateChild
$deletePermission = [System.DirectoryServices.ActiveDirectoryRights]::DeleteChild
# Create the access rules
$createAce = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
[System.Security.Principal.NTAccount]$userOrGroup,
$createPermission,
[System.Security.AccessControl.AccessControlType]::Allow,
$groupGuid,
[System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
$deleteAce = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
[System.Security.Principal.NTAccount]$userOrGroup,
$deletePermission,
[System.Security.AccessControl.AccessControlType]::Allow,
$groupGuid,
[System.DirectoryServices.ActiveDirectorySecurityInheritance]::All
)
# Get the security descriptor of the parent OU
$securityDescriptor = Get-Acl -Path "AD:$($ou.DistinguishedName)"
# Add the access rules to the security descriptor
$securityDescriptor.AddAccessRule($createAce)
$securityDescriptor.AddAccessRule($deleteAce)
# Set the updated security descriptor on the parent OU
Set-ACL -Path "AD:$($ou.DistinguishedName)" -AclObject $securityDescriptor
# Verify if the permissions have been added
$updatedSecurityDescriptor = Get-Acl -Path "AD:$($ou.DistinguishedName)"
$updatedAccessRules = $updatedSecurityDescriptor.Access | Where-Object { $_.IdentityReference -eq $userOrGroup }
if ($updatedAccessRules) {
Write-Host "Permissions to create and delete Group objects have been successfully granted to $userOrGroup on $($ou.DistinguishedName)"
$updatedAccessRules | format-Table -AutoSize
} else {
write-host "Failed to verify the delegation. Permission may not have been applied correctly." -ForegroundColor Red
}
gMSA Accounts delegation to create SPN
**SAT**
dsacls "OU=SQL,OU=EDME,OU=Accounts Group Managed System,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /I:S /G "SAT\SG-SQL-INSTANCEADMINS:RPWP;servicePrincipalName"
**AD**
dsacls "OU=SQL,OU=EDME,OU=Accounts Group Managed System,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\SG-SQL-INSTANCEADMINS:RPWP;servicePrincipalName"
dsacls "OU=SQL,OU=EIOD,OU=Accounts Group Managed System,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" /I:S /G "AD\SG-SQL-INSTANCEADMINS:RPWP;servicePrincipalName"
**DMZ**
dsacls "OU=SQL,OU=EIOD,OU=Account Group Managed System,OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /I:S /G "DMZ\SG-SQL-OSADMINS:RPWP;servicePrincipalName"
**SAT allow**
**“this account supports Kerberos AES 256 bit encryption”**
dsacls "OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /I:S /G "SAT\Delegation-User-msDS-SupportedEncryptionTypes:RPWP;msDS-SupportedEncryptionTypes"
dsacls "OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /I:S /G "SAT\SVC-WSG-ORCH-USRMNT:RPWP;msDS-SupportedEncryptionTypes"
**DMZ allow**
**“this account supports Kerberos AES 256 bit encryption”**
dsacls "OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /I:S /G "DMZ\Delegation-User-msDS-SupportedEncryptionTypes:RPWP;msDS-SupportedEncryptionTypes"
dsacls "OU=AccessControl,DC=dmz,DC=cbp,DC=dhs,DC=gov" /I:S /G "DMZ\SVC-WSG-ORCH-USRMNT:RPWP;msDS-SupportedEncryptionTypes"
**LAPS (ms-Mcs-AdmPwd read)**
#Install-Module -Name AdmPwd.PS ==# one time install==
Import-Module AdmPwd.PS
Set-AdmPwdReadPasswordPermission Identity "OU=Production,DC=ad,DC=cbp,DC=dhs,DC=gov" AllowedPrincipals "Delegation-Computer-ms-Mcs-AdmPwd"
Set-AdmPwdReadPasswordPermission Identity "OU=PreProduction,DC=ad,DC=cbp,DC=dhs,DC=gov" AllowedPrincipals "Delegation-Computer-ms-Mcs-AdmPwd"
Set-AdmPwdReadPasswordPermission Identity "OU=Servers Field,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" AllowedPrincipals "Delegation-Computer-ms-Mcs-AdmPwd"
==Review is LAPS is set==
Get-ADComputer -SearchBase "OU=Servers Field,OU=AccessControl,DC=ad,DC=cbp,DC=dhs,DC=gov" -Filter {ms-Mcs-AdmPwd -notlike "*"} | Where-Object { $_.Name -notlike "*-C*" }
Get-ADComputer -SearchBase "OU=PreProduction,DC=ad,DC=cbp,DC=dhs,DC=gov" -Filter {ms-Mcs-AdmPwd -notlike "*"} | Where-Object { $_.Name -notlike "*-C*" }
Get-ADComputer -SearchBase "OU=Production,DC=ad,DC=cbp,DC=dhs,DC=gov" -Filter {ms-Mcs-AdmPwd -notlike "*"} | Where-Object { $_.Name -notlike "*-C*" }
**Delegation of User Account Management 10/4/2024**
Delegation setting for any Users account management.
Example: Delegation-Leave-Of-Absence-Users and Delegation-Account-Special-Purpose-Users
![Exported image](Exported%20image%2020250808202100-3.png)
$OULocation = "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov"
$SecurityGroup = "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP"
#Setup User management
dsacls "$OULocation" /I:S /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP":GA
#Setup Group management
dsacls "$OULocation" /I:S /G "DomainName\GroupName":CCDCRP;group
#Setup OU management
dsacls "$OULocation" /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:CCDC;OU" /I:S
dsacls "$OULocation" /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:RP;group" /I:S
dsacls "$OULocation" /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:RPWP;displayName;user" /I:S
dsacls "$OULocation" /I:S /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP":RP;group
dsacls "$OULocation" /G "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:CCDC;group" /I:S
DSACLS "DC=ad,DC=cbp,DC=dhs,DC=gov" /G "SG-Delegation-User-Attributes:RPWP;L;user" /I:S
dsacls "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /I:S /G "SAT\Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:WPRPCA;OU"
dsacls "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov" /I:S /G "SAT\Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP:CCDC;organizational unit"
$ou = "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov"
$group = "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP"
# Get the security group object
$securityGroup = Get-ADGroup $group
# Grant permissions to the security group on the OU
Add-ADPermission -Identity $ou -User $securityGroup.Name -AccessRights CreateChild, DeleteChild -InheritanceType All -ObjectType "OrganizationalUnit"
$OrganizationalUnit = "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov"
$GroupName = "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP"
Set-Location AD:
$Group = Get-ADGroup -Identity $GroupName
$GroupSID = [System.Security.Principal.SecurityIdentifier] $Group.SID
$ACL = Get-Acl -Path $OrganizationalUnit
$Identity = [System.Security.Principal.IdentityReference] $GroupSID
$ADRight = [System.DirectoryServices.ActiveDirectoryRights] "CreateChild, DeleteChild"
$Type = [System.Security.AccessControl.AccessControlType] "Allow"
$InheritanceType = [System.DirectoryServices.ActiveDirectorySecurityInheritance] "None"
$ObjectType = [System.Guid]::Empty
$InheritedObjectType = [System.Guid]::Empty
$Rule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule($Identity, $ADRight, $Type, $ObjectType, $InheritedObjectType)
$ACL.AddAccessRule($Rule)
Set-Acl -Path $OrganizationalUnit -AclObject $ACL
$OrganizationalUnit = "OU=GROUPS-DMZ ICAM MANAGED MOCKUP,OU=AccessControl,DC=sat,DC=cbp,DC=dhs,DC=gov"
$ServiceUserName = "Delegation-GROUPS-DMZ ICAM MANAGED MOCKUP"
Set-Location AD:
$Group = Get-ADGroup -Identity $ServiceUserName
$GroupSID = [System.Security.Principal.SecurityIdentifier] $Group.SID
$ACL = Get-Acl -Path $OrganizationalUnit
$Identity = [System.Security.Principal.IdentityReference] $GroupSID
$Computers = [GUID]"bf967a86-0de6-11d0-a285-00aa003049e2"
$ResetPassword = [GUID]"00299570-246d-11d0-a768-00aa006e0529"
$ValidatedDNSHostName = [GUID]"72e39547-7b18-11d1-adef-00c04fd8d5cd"
$ValidatedSPN = [GUID]"f3a64788-5306-11d1-a9c5-0000f80367c1"
$AccountRestrictions = [GUID]"4c164200-20c0-11d0-a768-00aa006e0529"
$guidChangePassword = [GUID]"ab721a53-1e2f-11d0-9819-00aa0040529b"
$guidLockoutTime = [GUID]"28630ebf-41d5-11d1-a9c1-0000f80367c1"
#$guidPwdLastSet = [GUID]"bf967a0a-0de6-11d0-a285-00aa003049e2"
#$guidComputerObject = [GUID]"bf967a86-0de6-11d0-a285-00aa003049e2"
#$guidUserObject = [GUID]"bf967aba-0de6-11d0-a285-00aa003049e2"
$guidLinkGroupPolicy = [GUID]"f30e3bbe-9ff0-11d1-b603-0000f80367c1"
$guidGroupPolicyOptions = [GUID]"f30e3bbf-9ff0-11d1-b603-0000f80367c1"
$guidResetPassword = [GUID]"00299570-246d-11d0-a768-00aa006e0529"
$guidGroupObject = [GUID]"Guid BF967A9C-0DE6-11D0-A285-00AA003049E2"
$guidContactObject = [GUID]"5CB41ED0-0E4C-11D0-A286-00AA003049E2"
$guidOUObject = [GUID]"BF967AA5-0DE6-11D0-A285-00AA003049E2"
$guidPrinterObject = [GUID]"BF967AA8-0DE6-11D0-A285-00AA003049E2"
$guidWriteMembers = [GUID]"bf9679c0-0de6-11d0-a285-00aa003049e2"
$guidNull = [GUID]"00000000-0000-0000-0000-000000000000"
$guidPublicInformation = [GUID]"e48d0154-bcf8-11d1-8702-00c04fb96050"
$guidGeneralInformation = [GUID]"59ba2f42-79a2-11d0-9020-00c04fc2d3cf"
$guidPersonalInformation = [GUID]"77B5B886-944A-11d1-AEBD-0000F80367C1"
$guidGroupMembership = [GUID]"bc0ac240-79a9-11d0-9020-00c04fc2d4cf"
#$RuleCreateAndDeleteGroup = New-Object System.DirectoryServices.ActiveDirectoryAccessRule($Identity, "CreateChild, DeleteChild", "Allow", $guidGroupObject, "All")
$RuleCreateAndDeleteComputer = New-Object System.DirectoryServices.ActiveDirectoryAccessRule($Identity, "CreateChild, DeleteChild", "Allow", $Computers, "All")
$RuleResetPassword = New-Object System.DirectoryServices.ActiveDirectoryAccessRule ($Identity, "ExtendedRight", "Allow", $ResetPassword, "Descendents", $Computers)
$RuleValidatedDNSHostName = New-Object System.DirectoryServices.ActiveDirectoryAccessRule ($GroupSID, "Self", "Allow", $ValidatedDNSHostName, "Descendents", $Computers)
$RuleValidatedSPN = New-Object System.DirectoryServices.ActiveDirectoryAccessRule ($GroupSID, "Self", "Allow", $ValidatedSPN, "Descendents", $Computers)
$RuleAccountRestrictions = New-Object System.DirectoryServices.ActiveDirectoryAccessRule ($Identity, "ReadProperty, WriteProperty", "Allow", $AccountRestrictions, "Descendents", $Computers)
#$ACL.AddAccessRule($RuleCreateAndDeleteGroup)
$ACL.AddAccessRule($RuleCreateAndDeleteComputer)
$ACL.AddAccessRule($RuleResetPassword)
$ACL.AddAccessRule($RuleValidatedDNSHostName)
$ACL.AddAccessRule($RuleValidatedSPN)
$ACL.AddAccessRule($RuleAccountRestrictions)
Set-Acl -Path $OrganizationalUnit -AclObject $ACL
Computer Rename delegation
# Import the Active Directory module
Import-Module ActiveDirectory
# Define variables
$domain = "DC=ad,DC=cbp,DC=dhs,DC=gov" #
$delegatedGroup = "SG-WSG-RenameWRKST" # Group to receive the permissions
$ouPath = "OU=TestPermission,OU=WSG Workstations,OU=NWG001A,OU=NOVA,OU=NationalCapital,DC=ad,DC=cbp,DC=dhs,DC=gov" # Target OU where delegation will apply
# Get the group object
$group = Get-ADGroup $delegatedGroup
# Construct the DSACLS command to delegate the "Write Property" permission for the "Name" attribute
$dsaclsCommand = "dsacls.exe `"$ouPath`" /I:S /G `"$($group.SamAccountName):WP;Name;computer`""
# Execute the DSACLS command
Invoke-Expression $dsaclsCommand
Write-Host "Delegation rights to rename computer objects in $ouPath have been granted to $delegatedGroup"