A few of my AD 2003 user permission on SELF keep missing even if I have set it over and over again via the AD user and computer console. The same goes to "allow inheritable permission" check box, it would go unchecked again and again ....
As u can see in the attached picture, I have actually checked the "send as", "receive as" and "read account restriction" permission 1 hour before this, everything seems ok when I test sending and receiving emails for that user. However the permissions will go missing after 1 hour or so. The same goes to "allow inheritable permission" check box
I earlier thought it could be due to the level of administrator privilege I was using, like a lower level permission administrator cannot undo the settings done by a high level administrator. So tried using the Enterprise administrator, it didn’t help .. the permission got reset after 1-2 hrs.
How many DC are in the domain and DC which you login to make changes of the Object holds any Role .Did you check if the changes has been replicate to other DC's in the Domain.
suspect that the changed happend onthis DC is not replicating to other DC, create a test user and check if it get replicated to other DC's in the Domain.
Thanks guys .. let me check and get back to you....
Panda 5888
ASKER
Hi gaurav2rawat
No errors in repadmin /showreps /v
Under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters, there were no #define DSA_WRITABLE_* entries
when I remove the user from Printer operator group ... their permission stays, but once I put them back to Printer operator group, their permission goes missing again.
The missing permissions are "Send As right from the user and Allow inheritable permissions from parent to propagate to this object check box no longer selected."
Yes. That's expected behavior as you could read in the articles me and others have linked. The MS article you linked offers a best practice and a workaround. Any questions left?
suspect that the changed happend onthis DC is not replicating to other DC, create a test user and check if it get replicated to other DC's in the Domain.