1 00:00:00,150 --> 00:00:07,480 My delegating GP or related tasks you can just rebuild their administrative work load across the enterprise. 2 00:00:07,530 --> 00:00:14,130 You can task one group was created and an additive GP GPO while another group performs a reporting and 3 00:00:14,130 --> 00:00:19,720 analysis duties a third group might be in charge of great and w my filters. 4 00:00:19,740 --> 00:00:27,360 You can delegate the following group policy tasks creating GPO edit and GPO manage and group policy 5 00:00:27,360 --> 00:00:35,640 links with a site domain or or your performing group policy module and analysis on a given domain or 6 00:00:35,670 --> 00:00:37,810 your reading group policy results. 7 00:00:37,830 --> 00:00:45,780 Data for objects in a given domain or you create in w may have filters in a domain a group policy creator 8 00:00:45,840 --> 00:00:51,960 owners group allows members who create new GPO was to edit or delete them. 9 00:00:51,990 --> 00:00:54,800 So what our group policy default permissions. 10 00:00:54,810 --> 00:01:00,450 By default the following user and groups have full control over GPO management. 11 00:01:00,450 --> 00:01:07,730 They are domain admins enterprise admins group policy creator owners and local system. 12 00:01:07,840 --> 00:01:15,480 Authenticated user group has read and apply group policy permissions to all GPL by default only domain 13 00:01:15,480 --> 00:01:21,400 admins enterprise segments and group policy creator owners can create new GPO. 14 00:01:21,510 --> 00:01:25,440 You can use two methods to grant a group or user. 15 00:01:25,440 --> 00:01:32,070 This arrived at the user or group to the group policy create creator owners group or explicitly grant 16 00:01:32,130 --> 00:01:38,100 the group or user permission to create GP is by using the GP suit to added a GPO. 17 00:01:38,090 --> 00:01:42,450 The user must have both read and write access to the GPO. 18 00:01:42,450 --> 00:01:49,350 You can grant this permission by using the JPM see their ability to link GPO to a container is a permission 19 00:01:49,350 --> 00:01:55,950 that is specific to that container in the JPM see you can manage this permission by using that delegation 20 00:01:55,950 --> 00:01:57,420 tap on the container. 21 00:01:57,420 --> 00:02:05,190 You also can delegated by using delegation of control visa inactive director you reuse or some computer. 22 00:02:05,220 --> 00:02:12,740 You can also delegate the ability to use the report and tools in the same way by using Gypsy or by using 23 00:02:12,760 --> 00:02:17,600 delegation of control reserved inactive directory users and computers. 24 00:02:17,610 --> 00:02:20,280 The same is for double are my filters. 25 00:02:20,340 --> 00:02:28,260 You can create and manage W and my filters in the same way by using their GP MCO or by union delegation 26 00:02:28,260 --> 00:02:32,370 of controlled visa inactive directory users on computers. 27 00:02:32,370 --> 00:02:38,980 Now a small test for you members of visibility built in HDD as groups can create GP was by default. 28 00:02:39,000 --> 00:02:46,600 The options are domain Edmonds account operators enterprise elements GPO Edmonds or group policy creator 29 00:02:46,620 --> 00:02:47,190 owners.