Delegating Active Directory permissions
Have you ever seen a company where almost everyone has Domain Admin access? Anyone who has been in this industry for long enough will respond with a resounding YES. Some companies hand out Domain Admin rights to anyone who asks for it, usually because the user needs to do something that's slightly more powerful than the default user and the administrators don't know how to delegate Active Directory permissions. Sometimes, it's a vendor who comes along and hasn't bothered to do their research into exactly which Active Directory permissions their software needs in order to do the job.
For example, if you have a helpdesk individual who needs to be able to change a user's name, but not create accounts or change user passwords, then why would you give that person Domain Admin? But a lot of companies do, simply because they don't know the power of Active Directory's delegation.
Getting started
For this, we...