Solved

Can Active Directory Global Groups be applied to the ACL using CACLS?

Posted on 2007-12-04
3
817 Views
Last Modified: 2010-04-21
I'm running a batch file to launch CACLS to modify permissions.  Is it possible to apply Active Directory Global Groups to the ACL using CACLS?  User accounts are working fine in the script.  

The script appears to simply ignore the global groups.  The global groups do not have any spaces.

I have tried encasing the group name with quotes (").

I've tried using the domain name slash domain\groupname in the command line (with and without the quotes)  

I'm running out of ideas.  Thanks.
0
Comment
Question by:scuba101
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 19

Accepted Solution

by:
SteveH_UK earned 125 total points
ID: 20405596
Can you confirm that the groups in question are "security groups" and not "distribution groups" in Active Directory Users & Computers.  Distribution Groups cannot be used in ACLs, but Security Groups (Universal, Global and Local) can all be used in ACLs.

It is best practice to use domain local groups to assign security and global groups to represent groups of users.  You can then combine global groups into universal groups where they are needed to be collected as a set.

Also, be warned, CACLS and XCACLS are not great with permission inheritance.  You may want to look at Powershell:  http://www.microsoft.com/technet/technetmag/issues/2006/12/PowerShell/
0
 
LVL 1

Expert Comment

by:Voo_pg
ID: 20418685
CACLS myfile.txt /E /G "Power Users":F

Yes, only security groups will work. The above command would give Power Users, Full Control of myfile.txt

What syntax have you been using?
0
 

Author Closing Comment

by:scuba101
ID: 31412653
The problem I was having had to do with an inaccurate path - once I knew AD Global Groups worked, it narrowed down the search.  THanks.
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you receive another warning that your shared drive is almost full and you have asked your users to clean out old files again and again, here is a single command that may help. This command will place all the files that have not been used rec…
Introduction: Recently, I got a requirement to zip all files individually with batch file script in Windows OS. I don't know much about scripting, but I searched Google and found a lot of examples and websites to complete my task. Finally, I was ab…
Come and listen to Percona CEO Peter Zaitsev discuss what’s new in Percona open source software, including Percona Server for MySQL (https://www.percona.com/software/mysql-database/percona-server) and MongoDB (https://www.percona.com/software/mongo-…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question