Link to home
Start Free TrialLog in
Avatar of bccops
bccopsFlag for United States of America

asked on

How to query for all objects in AD which do NOT have allow inheritable permissions enabled

How can I write an LDAP query for all objects in Active Directory that do NOT have "Allow inheritable permissions from the parent to propagate to this object.." enabled. If not possible in an LDAP query is there some alternate method to produce a report of all these objects other than manually checking each of them?
ASKER CERTIFIED SOLUTION
Avatar of Chris Dent
Chris Dent
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of bccops

ASKER

This looks like it's what I need -- will test the script soon and report results.

Cool, yell if you need any code changes.

Chris
Avatar of bccops

ASKER

This is precisely what I needed.

Thank you