Link to home
Start Free TrialLog in
Avatar of jskfan
jskfanFlag for Cyprus

asked on

SELF group in Acrive Directory

I would like to knwo what is
SELF group in Acrive Directory?

do I have to leave it or remove it?

Thanks
Avatar of tomerlei
tomerlei

Self is not a real group, its a relative group.
Its like the Everyone and Authenticated Users groups.
For example if you add a computer account to the AD and you want to apply a security permission on that computer and you want to give this permission to the same computer account you give it to the SELF group.

Here microsoft gives an example of using the self group for allowing a computer to use a different DNS name:
http://support.microsoft.com/default.aspx?scid=kb;en-us;320187
Avatar of jskfan

ASKER

<<<<For example if you add a computer account to the AD and you want to apply a security permission on that computer and you want to give this permission to the same computer account you give it to the SELF group.>>>>>>>>

can you explain this? can't we create a group and give it permission on the computer account or use authenticated users or everyone?

It's still not clear for me what the default SELF group is for.


I'm sorry, i guess i was pretty unclear.
here is a better explantion on the self group:

"A placeholder in an ACE on a user, group, or computer object in Active Directory. When you grant permissions to Principal Self, you grant them to the security principal represented by the object. During an access check, the operating system replaces the SID for Principal Self with the SID for the security principal represented by the object. "

Taken form http://www.ss64.com/ntsyntax/security_groups.html.

It's pretty simple, it just redirects to the object that the security permission was granted on.
Avatar of jskfan

ASKER

but my question was every group or user name that shows up on the security tab of an object has permissions(if they are granted) on that object.
 so I don't see where SELF group  would differ from others.
ASKER CERTIFIED SOLUTION
Avatar of tomerlei
tomerlei

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial