[Samba] role delegation

Patrick Goetz pgoetz at math.utexas.edu
Fri Oct 29 21:34:15 UTC 2021

I would like to have a user with limited domain admin capabilities; 
namely the ability to add new users and add users to groups, with the 
ideal being to also able to help users reset their password and 
create/delete groups. But this user would not be able to create OU's, 
edit Group Policy, or do anything else other than work with users and 
groups.  Is such a thing even possible?

A related and much easier (let's call it dumb, should have RTFMed) 
quesetion, is what's involved in making other users full domain admins?

