Active Directory : control flags for a security descriptor

From: Bob (homer_at_hotmail.com)
Date: 07/22/04


Date: 22 Jul 2004 12:47:10 GMT

Hi,

After setting control flags for a security descriptor to this :

ADS_SD_CONTROL_SE_DACL_PROTECTED

Using this line :

sd.Control =
ADS_SD_CONTROL.ENUM.ADS_SD_CONTROL_SE_DACL_PROTECTED

The "Allow inheritable permissions from parent" is unchecked BUT
ACEs herited from parent are still there (copied, or even still
herited, which is impossible).

Can someone please told me how to delete ACEs herited from
parent when setting the control flag to
ADS_SD_CONTROL_SE_DACL_PROTECTED ?

Thanks,

----------------------------------------------
Posted with NewsLeecher v1.0 beta 25
 * Binary Usenet Leeching Made Easy
 * http://www.newsleecher.com/?usenet
----------------------------------------------



Relevant Pages

  • Re: Bob Qin - Please see my follow-up to your reply
    ... Yes I did recreate the delegation after moving the users to the OU. ... Where do I find the "Allow inheritable permissions from parent to propagate ...
    (microsoft.public.windows.server.migration)
  • Re: Bob Qin - Please see my follow-up to your reply
    ... Did you recreate the delegation after you move all the users to a OU? ... You can also check if the "Allow inheritable permissions from parent to ... propagate to this object" is enabled in the properties of the user with ...
    (microsoft.public.windows.server.migration)
  • Re: AD user account not able to inherit permission from AD
    ... state of the Allow inheritable permissions from parent to propagate to ... the object checkbox on parent object. ... the child will inherit this overwritten ACL. ... child object itself should have this option checked. ...
    (microsoft.public.windows.server.sbs)
  • RE: Restricted Access snuck up on me!
    ... Under the security tab, "Allow inheritable permissions from ... parent to propogate to this object" was not checked on those items. ...
    (microsoft.public.inetserver.iis)
  • Re: GP event error 1058 & 1030 ?
    ... On the Security tab, click Advanced, click to clear the Allow ... inheritable permissions from parent to propagate to this object check ...
    (microsoft.public.windows.server.active_directory)

Quantcast