Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

AD user permission missing

Posted on 2012-12-21
13
Medium Priority
?
821 Views
Last Modified: 2013-01-04
Hi,

A few of my AD 2003 user permission on SELF keep missing even if I have set it over and over again via the AD user and computer console. The same goes to "allow inheritable permission" check box, it would go unchecked again and again ....

As u can see in the attached picture, I have actually checked the "send as",  "receive as" and "read account restriction" permission 1 hour before this, everything seems ok when I test sending and receiving emails for that user. However the permissions will go missing after 1 hour or so. The same goes to "allow inheritable permission" check box

I earlier thought it could be due to the level of administrator privilege I was using, like a lower level permission administrator cannot undo the settings done by a high level administrator. So tried using the Enterprise administrator, it didn’t help  .. the permission got reset after 1-2 hrs.

DL
self.jpg
0
Comment
Question by:Panda 5888
  • 7
  • 2
  • 2
  • +2
13 Comments
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38712508
How many DC are in the domain and DC which you login to make changes of the Object holds any Role .Did you check if the changes has been replicate to other DC's in the Domain.
suspect that the changed happend onthis DC is not replicating to other DC, create a test user and check if it get replicated to other DC's in the Domain.
0
 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38713972
Try checking for replication errors using repadmin /showreps /v
also try checking if the server is in usn rollback state
under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters

and look for either of these entries
#define DSA_WRITABLE_GEN 1
#define DSA_WRITABLE_NO_SPACE 2
#define DSA_WRITABLE_USNROLLBCK 4
#define DSA_WRITABLE_CORRUPT_UTDV 8

If it is then follow kb
http://support.microsoft.com/kb/2023007
0
 
LVL 57

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 38714238
0
Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38714274
Its only for the highly privileged accounts and that too for tools like people update
More importantly in your case, if its happening with every user then its probably a usnroll back or a replication issue
0
 
LVL 24

Assisted Solution

by:Sandeshdubey
Sandeshdubey earned 500 total points
ID: 38717828
AdminSDHolder - or where did my permissions go?
http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx

Delegated permissions are not available and inheritance is automatically disabled
http://support.microsoft.com/kb/817433
0
 

Author Comment

by:Panda 5888
ID: 38717840
Thanks guys .. let me check and get back to you....
0
 

Author Comment

by:Panda 5888
ID: 38717864
Hi gaurav2rawat
No errors in repadmin /showreps /v
Under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters, there were no #define DSA_WRITABLE_* entries
0
 

Author Comment

by:Panda 5888
ID: 38717867
Hi Venurajav, I only have 2 DC, they are replicating ... new user is replicated to another DC
0
 

Author Comment

by:Panda 5888
ID: 38717869
Hi gaurav2rawat ... it is not happening to all users, only a like 20/1000 users are having this problem..
0
 

Accepted Solution

by:
Panda 5888 earned 0 total points
ID: 38717894
Your suggestions lead me to "members of a protected group" direction ... then I found this http://support.microsoft.com/kb/907434 which is exactly describe my situation, after a little more investigation I found that all those involved are members of the Printer Operator, which is a protected group ... I've removed one of the user from Printer Operator, I will wait for 1-2 hrs before reseting his account with the correct permission, and then wait another 1-2 hrs to see if those permisson stays...
0
 

Author Comment

by:Panda 5888
ID: 38723019
when I remove the user from Printer operator group ... their permission stays, but once I put them back to Printer operator group, their permission goes missing again.

The missing permissions are "Send As right from the user and Allow inheritable permissions from parent to propagate to this object check box no longer selected."
0
 
LVL 57

Expert Comment

by:McKnife
ID: 38723066
Yes. That's expected behavior as you could read in the articles me and others have linked. The MS article you linked offers a best practice and a workaround. Any questions left?
0
 

Author Closing Comment

by:Panda 5888
ID: 38743261
working solution
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

High user turnover can cause old/redundant user data to consume valuable space. UserResourceCleanup was developed to address this by automatically deleting user folders when the user account is deleted.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question