Re: Propagating permissions to child Objects



You have disallowed inheritance at multiple locations.
Thus, NTFS grants in the parental chain above those
location will have no impact at or past the points where
inheritance is blocked.

You want the cake and to eat it.

Probably the best you could do is to script the change,
adding the new group at each point, or, if you had the
prior insight to define this permissioning structure in
a security template you could just paste the new grant
into each line in the Filesystem section for the structure.

Perhaps you ought go to MS.com/downloads and get
xcacls.vbs and then make a batch file that will execute
this X times for the X points where inheritance is blocked.

Roger

"Valerie C" <valeriec@xxxxxxxxxxxxxxxxxx> wrote in message
news:C16ECC9C-0CD9-4857-BEA1-E9C9D688497A@xxxxxxxxxxxxxxxx
We have a directory tree that we want to have each levels permissions
assigned separately, so have cleared the "allow inheritable permissions
from
parent to propagate to this object". The tree has many layers of
subfolders.

Now we need to add someone to the top layer and need to have her rights
propagate to all the child objects, while leaving the other permissions in
place, as she is going to become responsible for giving users permissions.
How do I do this without adding her manually to every folder?

Thanks for your help - I'm a security newbie and the experienced person is
on vacation (why do these issues always come up when your backup is
away???).

--
Valerie Christopher


.



Relevant Pages

  • Re: ADAM And ACLs
    ... The ACLs for the OU which is the parent of the object below are: ... Effective Permissions on this object are: ... SPECIAL ACCESS ... for the naming context and is usually present by inheritance, ...
    (microsoft.public.windows.server.active_directory)
  • Re: NTFS inherited permissions bug on W2K
    ... NTFS inherited permissions bug on W2K ... >> Inheritance has always been present in NT. ... >actually copied to the inherited objects' ACLs). ...
    (NT-Bugtraq)
  • Re: AD User Objects & Permission Inheritance
    ... I went ahead and granted the Account Operators built in group rights on the adminSDholder object according to what I want the OU admins to have. ... I went ahead and enabled inheritance on the> adminSDholder object to verify that this indeed was the cause and 60> minutes ... > later all user objects began to inherit permissions again. ...
    (microsoft.public.win2000.active_directory)
  • Re: Permissions resetting in Blocked Inheritance OUs
    ... If the ACL that is on the AdminSDHolder object is ... Delegated permissions are not available and inheritance is automatically ... "You do not have sufficient permissions in the Domain" error message occurs ... This user account is in an OU that has Blocked ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions resetting in Blocked Inheritance OUs
    ... If the ACL that is on the AdminSDHolder object is ... Delegated permissions are not available and inheritance is automatically ... "You do not have sufficient permissions in the Domain" error message occurs ... This user account is in an OU that has Blocked ...
    (microsoft.public.windows.server.active_directory)

Quantcast