Permissions to Rename Domain joined Computer Objects

Hi

We have enabled delegate access via  Active Roles for our service desk team.

They have full control over all objects in AD however they are unable to rename domain joined computers due to permissions. 

Does anyone know if there is a permission in ARS that's required to allow them to rename objects? Ideally we want to manage this through ARS rather than delegated control in AD. 

TIA. 

  • See this article.

    Though probably not worth the engineering effort, you could setup and delegate accesss to an automation workflow containing a script activity to facilitate the rename from the computer side.  The biggest challenge here though would be allowing the script to execute on the remote host.  Unless you already have something like this setup for software distribution for example, IMO it's probably more trouble than it's worth.