Re: AD Users & Computers Permissions Issue

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/10/04


Date: Fri, 09 Apr 2004 22:41:05 GMT

I notice that on accounts that belonged to higher level groups such as
administrators, backup operators, server operators, etc that inheritance has been
removed probably to keep delegation from applying to them. You may want to check to
see if those accounts are just in the users group level or not. --- Steve

"Jeff Doty" <anonymous@discussions.microsoft.com> wrote in message
news:1a90501c41e5f$e2091930$a401280a@phx.gbl...
> Hi All,
>
> I have a strange little problem. My help desk has
> delegated authority to deal with the user accounts in
> several OUs, however there are a couple of accounts that
> they don't have permissions. I have checked and on those
> accounts the permissions are not being inherited from the
> parent OU. I can check the box that says to inherit
> permissions, but as soon as I close Users & Computers
> those accounts revert to not inheriting the permissions.
> Does anyone know what is going on? I need my Help Desk to
> be able to unlock those accounts, disable them, reset the
> passwords, etc. Thanks in Advance.
>
> Jeff :-)
>



Relevant Pages

  • Re: Changes to ACL disappear
    ... Implementing Method 2 did allow inheritance on all "protected groups" but it ... AdminCount attribute from 1 to 0 for administrative accounts (which the ... >> for adminSDHolder. ...
    (microsoft.public.windows.server.security)
  • Re: adminSDholder and permissions resets
    ... Delegated permissions are not available and inheritance is ... even after I explicitly allow inheritance. ... That's what the script (just above the ldifde command in the KB ... Do you have any idea why this is still set even when I remove my accounts ...
    (microsoft.public.exchange.admin)
  • Re: AD Users & Computers Permissions Issue
    ... They are Domain Admin accounts. ... my Help Desk be able to reset the Domain Admins accounts ... that inheritance has been ...
    (microsoft.public.win2000.security)
  • Re: Security Group Keeps getting removed???
    ... ACL on all security principals (users, groups, and machine accounts) present ... Delegated permissions are not available and inheritance is automatically ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Delegating AD Rights (Enable/Disable Accounts)
    ... I will definitely pass it on to my Customer ... user accounts in AD to non-admin staff so that they will be able to ... permissions as Domain User rights will work just fine. ... The UMRA ...
    (microsoft.public.windows.server.scripting)