Solved

AD is removing permissions from objects inside OU

Posted on 2006-07-17
1
194 Views
Last Modified: 2010-04-18
Hi,

when i apply permissions to an OU inside AD, all is good for new items created inside the OU, however for existing items, after their permissions are updated, the newer permissions from the OU have been removed from the item. I don't understand why/how

could someone please give me any idea.

Cheers
Peter
0
Comment
Question by:hooch_au78
1 Comment
 
LVL 51

Accepted Solution

by:
Netman66 earned 500 total points
ID: 17126892
This is a function of AdminSDHolder.  Members of protected groups will always be under the contol of this attribute.  Permissions will revert back at next policy refresh interval.

This article sort of explains it:

http://support.microsoft.com/kb/817433/en-us


This is a good article written by a peer Server MVP - good reading:

http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This is a video that shows how the OnPage alerts system integrates into ConnectWise, how a trigger is set, how a page is sent via the trigger, and how the SENT, DELIVERED, READ & REPLIED receipts get entered into the internal tab of the ConnectWise …

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now