Skip to main content

Applying Atria Delegated Permissions to AD Organizational Units

Overview

Ensure-AtriaDelegatedOU is an Atria function that validates if the Active Directory Organizational Unit (OU) exists under a specified parent DN, creates it if missing, then applies Atria delegated permissions to the OU.


Use Case

New or Existing Active Directory OU(s) needed to be managed by Atria.


Prerequisites

  • Preferrably to run this on the Atria Provisioning Server
  • At least Windows PowerShell 5.1
  • RSAT installed with the ActiveDirectory module available.
  • Permissions to create OUs in the target path
  • Atria.Tools PowerShell module installed and available in the session

Required AD Groups

The following groups must exist in Active Directory. These groups are available starting Atria version 15.30.x

  • Atria Delegated Contact Management
  • Atria Delegated Group Management
  • Atria Delegated OU Management
  • Atria Delegated User Management
  • Atria Delegated Dacl Management
  • CortexAdmins
  • CortexReadOnly

Parameters

ParameterTypeRequiredDescriptionExample
OUNameStringYesName of the OU to create or verify.CSPHosting
ParentPathStringYesParent DN where the OU will exist.DC=yourdomain,DC=local or OU=Companies,DC=yourdomain,DC=local

What the Script Does

  1. Imports the Active Directory module
  2. Builds the target OU DN as OU=<OUName>,<ParentPath>
  3. Checks if the OU exists
  4. Creates the OU if it does not exist
  5. Applies Atria Delegated Permissions on the OU

Example Usage (PowerShell) - Administrator Mode

Import-Module Atria.Tools
Ensure-AtriaDelegatedOU -OUName "CSPHosting" -ParentPath "DC=yourdomain,DC=local"

Support

If you encounter any issues or require assistance, contact:
📧 support@getatria.com