Solved

Active Directory User Account Permissions Mysteriously Reset

Posted on 2006-06-22
3
287 Views
Last Modified: 2008-02-26
I am having trouble getting permissions set in Active Directory to "Set".  I am setting a permission for a user account to have the "Send As" permission.  what happens is I set the permission and test that it works.  some time later (about an hour or so) I'll get a call that the user cannot on behalf again.  I check the permissions and the one I created has mysteriously disappeared!  this also happens if I use the inherit permissions tickbox, I go back and the tick is removed and the permissions are gone!  p

Please help as this is driving me round the twist.  
0
Comment
Question by:FOSnet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 26

Accepted Solution

by:
Pber earned 250 total points
ID: 17010491
It's most likely those users are in protected groups.  Once an hour the DC will compare ACLs on all objects for those objects in admin groups with what is in AdminSDHolder container, if they are different it resets the permission on those objects to what is set on the AdminSDHolder object.

Check out these articles


Description and Update of the Active Directory AdminSDHolder Object

http://support.microsoft.com/?id=232199
AdminSDHolder Thread Affects Transitive Members of Distribution Groups
http://support.microsoft.com/?id=318180
Delegated permissions are not available and inheritance is automatically
disabled
http://support.microsoft.com/?id=817433
AdminSDHolder Object Affects Delegation of Control for Past Administrator
Accounts
http://support.microsoft.com/?id=306398
Security tab of the adminSDHolder object does not display all properties
http://support.microsoft.com/?id=301188
"You do not have sufficient permissions in the Domain" error message occurs
and Exchange Setup does not respond
http://support.microsoft.com/?id=319966
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Nslookup is a command line driven utility supplied as part of most Windows operating systems that can reveal information related to domain names and the Internet Protocol (IP) addresses associated with them. In simple terms, it is a tool that can …
We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question