[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

AD user permission missing

Posted on 2012-12-21
13
Medium Priority
?
838 Views
Last Modified: 2013-01-04
Hi,

A few of my AD 2003 user permission on SELF keep missing even if I have set it over and over again via the AD user and computer console. The same goes to "allow inheritable permission" check box, it would go unchecked again and again ....

As u can see in the attached picture, I have actually checked the "send as",  "receive as" and "read account restriction" permission 1 hour before this, everything seems ok when I test sending and receiving emails for that user. However the permissions will go missing after 1 hour or so. The same goes to "allow inheritable permission" check box

I earlier thought it could be due to the level of administrator privilege I was using, like a lower level permission administrator cannot undo the settings done by a high level administrator. So tried using the Enterprise administrator, it didn’t help  .. the permission got reset after 1-2 hrs.

DL
self.jpg
0
Comment
Question by:Panda 5888
  • 7
  • 2
  • 2
  • +2
13 Comments
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38712508
How many DC are in the domain and DC which you login to make changes of the Object holds any Role .Did you check if the changes has been replicate to other DC's in the Domain.
suspect that the changed happend onthis DC is not replicating to other DC, create a test user and check if it get replicated to other DC's in the Domain.
0
 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38713972
Try checking for replication errors using repadmin /showreps /v
also try checking if the server is in usn rollback state
under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters

and look for either of these entries
#define DSA_WRITABLE_GEN 1
#define DSA_WRITABLE_NO_SPACE 2
#define DSA_WRITABLE_USNROLLBCK 4
#define DSA_WRITABLE_CORRUPT_UTDV 8

If it is then follow kb
http://support.microsoft.com/kb/2023007
0
 
LVL 58

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 38714238
0
Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38714274
Its only for the highly privileged accounts and that too for tools like people update
More importantly in your case, if its happening with every user then its probably a usnroll back or a replication issue
0
 
LVL 24

Assisted Solution

by:Sandeshdubey
Sandeshdubey earned 500 total points
ID: 38717828
AdminSDHolder - or where did my permissions go?
http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx

Delegated permissions are not available and inheritance is automatically disabled
http://support.microsoft.com/kb/817433
0
 

Author Comment

by:Panda 5888
ID: 38717840
Thanks guys .. let me check and get back to you....
0
 

Author Comment

by:Panda 5888
ID: 38717864
Hi gaurav2rawat
No errors in repadmin /showreps /v
Under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters, there were no #define DSA_WRITABLE_* entries
0
 

Author Comment

by:Panda 5888
ID: 38717867
Hi Venurajav, I only have 2 DC, they are replicating ... new user is replicated to another DC
0
 

Author Comment

by:Panda 5888
ID: 38717869
Hi gaurav2rawat ... it is not happening to all users, only a like 20/1000 users are having this problem..
0
 

Accepted Solution

by:
Panda 5888 earned 0 total points
ID: 38717894
Your suggestions lead me to "members of a protected group" direction ... then I found this http://support.microsoft.com/kb/907434 which is exactly describe my situation, after a little more investigation I found that all those involved are members of the Printer Operator, which is a protected group ... I've removed one of the user from Printer Operator, I will wait for 1-2 hrs before reseting his account with the correct permission, and then wait another 1-2 hrs to see if those permisson stays...
0
 

Author Comment

by:Panda 5888
ID: 38723019
when I remove the user from Printer operator group ... their permission stays, but once I put them back to Printer operator group, their permission goes missing again.

The missing permissions are "Send As right from the user and Allow inheritable permissions from parent to propagate to this object check box no longer selected."
0
 
LVL 58

Expert Comment

by:McKnife
ID: 38723066
Yes. That's expected behavior as you could read in the articles me and others have linked. The MS article you linked offers a best practice and a workaround. Any questions left?
0
 

Author Closing Comment

by:Panda 5888
ID: 38743261
working solution
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
The article explains the process to deploy a Self-Service password reset portal I developed a few years ago. Hopefully, it will prove useful to someone.  Any comments, bug reports etc. are welcome...
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question