Solved

Can Active Directory Global Groups be applied to the ACL using CACLS?

Posted on 2007-12-04
3
811 Views
Last Modified: 2010-04-21
I'm running a batch file to launch CACLS to modify permissions.  Is it possible to apply Active Directory Global Groups to the ACL using CACLS?  User accounts are working fine in the script.  

The script appears to simply ignore the global groups.  The global groups do not have any spaces.

I have tried encasing the group name with quotes (").

I've tried using the domain name slash domain\groupname in the command line (with and without the quotes)  

I'm running out of ideas.  Thanks.
0
Comment
Question by:scuba101
3 Comments
 
LVL 19

Accepted Solution

by:
SteveH_UK earned 125 total points
ID: 20405596
Can you confirm that the groups in question are "security groups" and not "distribution groups" in Active Directory Users & Computers.  Distribution Groups cannot be used in ACLs, but Security Groups (Universal, Global and Local) can all be used in ACLs.

It is best practice to use domain local groups to assign security and global groups to represent groups of users.  You can then combine global groups into universal groups where they are needed to be collected as a set.

Also, be warned, CACLS and XCACLS are not great with permission inheritance.  You may want to look at Powershell:  http://www.microsoft.com/technet/technetmag/issues/2006/12/PowerShell/
0
 
LVL 1

Expert Comment

by:Voo_pg
ID: 20418685
CACLS myfile.txt /E /G "Power Users":F

Yes, only security groups will work. The above command would give Power Users, Full Control of myfile.txt

What syntax have you been using?
0
 

Author Closing Comment

by:scuba101
ID: 31412653
The problem I was having had to do with an inaccurate path - once I knew AD Global Groups worked, it narrowed down the search.  THanks.
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Introduction: Recently, I got a requirement to zip all files individually with batch file script in Windows OS. I don't know much about scripting, but I searched Google and found a lot of examples and websites to complete my task. Finally, I was ab…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now