Follow the steps below to create an access template to only allow a user to modify user telephone numbers in Active Directory through the Active Roles MMC.
- Navigate to Access Templates within the MMC
- Right click and select New > Access Template
- Type in an approriate name
- Click Next
- Click Add
- Toggle Only the following classess radio button
- Select the Domain check box and click Next
- Toggle Object access
- Check the List Object check box
- Click Finish
- Follow steps 5 to 10 again this time add Read All Properties
- Follow steps 5 to 10 again and for step 7 select Organizational Unit
- Set the same two permissions that was set for Domain
- Do this again for User with the same permissions
- Add Write Telephone Number permissions for User
- Click Next
- Click Finish
Next link the access template to a user and directory object. Follow the steps below:
- Right click on the access template
- Select Links
- Click Add
- Click Next
- Click Add
- Type in the Domain or OU where this will be applied
- Click OK
- Click Next
- Click Add
- Type in the user to apply this template
- Click OK
- Click Next
- Click Next
- Click Next
- Click Finish