AD account will not retain permissions

Posted on 2006-06-08
Last Modified: 2010-04-18
I run a Win 2003 AD enterprise.  I have a user account that will simply not retain permissions that are set on it under the advanced features, security tab in AD Users and Computers.  I check the allow inheritable permissions box under advanced and I also have applied a couple of explicit permissions on this object. I then push out a replication using replmon to make sure the other DC's are updated.  Within 45 mins or so the allow inheritable box is unchecked agaion and the explicit advanced permissions I had set are gone.  I have tried this succesfully wth other users in the same OU and it worked fine.  I have also reviewed this users attributes in ADSI Edit and nothing seems to look wrong - although I do not know every single attribute.  This happened to me a few months ago with another account in a different OU and all I could do was delete and recreate the object.  I'd like to avoid doing that if possible but I am not sure what else I can do or what would cause the object to not retain the permissions settings.  
Question by:mrsmileyns
    LVL 82

    Accepted Solution

    If the user objects in question are (or have been at some point) members of the Administrators group (or another protected group; this can include nested groups!), then that's why. Control over protected groups can by default not be delegated.

    Delegated Permissions Are Not Available and Inheritance Is Automatically Disabled

    Description and Update of the Active Directory AdminSDHolder Object

    Author Comment

    This is very interesting - I am not sure if this user was part of a protected group in the past but it would explain the behavior.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
    Learn about cloud computing and its benefits for small business owners.
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now