Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

AD user permission missing

Posted on 2012-12-21
13
Medium Priority
?
812 Views
Last Modified: 2013-01-04
Hi,

A few of my AD 2003 user permission on SELF keep missing even if I have set it over and over again via the AD user and computer console. The same goes to "allow inheritable permission" check box, it would go unchecked again and again ....

As u can see in the attached picture, I have actually checked the "send as",  "receive as" and "read account restriction" permission 1 hour before this, everything seems ok when I test sending and receiving emails for that user. However the permissions will go missing after 1 hour or so. The same goes to "allow inheritable permission" check box

I earlier thought it could be due to the level of administrator privilege I was using, like a lower level permission administrator cannot undo the settings done by a high level administrator. So tried using the Enterprise administrator, it didn’t help  .. the permission got reset after 1-2 hrs.

DL
self.jpg
0
Comment
Question by:Panda 5888
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 2
  • 2
  • +2
13 Comments
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38712508
How many DC are in the domain and DC which you login to make changes of the Object holds any Role .Did you check if the changes has been replicate to other DC's in the Domain.
suspect that the changed happend onthis DC is not replicating to other DC, create a test user and check if it get replicated to other DC's in the Domain.
0
 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38713972
Try checking for replication errors using repadmin /showreps /v
also try checking if the server is in usn rollback state
under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters

and look for either of these entries
#define DSA_WRITABLE_GEN 1
#define DSA_WRITABLE_NO_SPACE 2
#define DSA_WRITABLE_USNROLLBCK 4
#define DSA_WRITABLE_CORRUPT_UTDV 8

If it is then follow kb
http://support.microsoft.com/kb/2023007
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 38714238
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 3

Assisted Solution

by:gaurav2rawat
gaurav2rawat earned 1000 total points
ID: 38714274
Its only for the highly privileged accounts and that too for tools like people update
More importantly in your case, if its happening with every user then its probably a usnroll back or a replication issue
0
 
LVL 24

Assisted Solution

by:Sandeshdubey
Sandeshdubey earned 500 total points
ID: 38717828
AdminSDHolder - or where did my permissions go?
http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx

Delegated permissions are not available and inheritance is automatically disabled
http://support.microsoft.com/kb/817433
0
 

Author Comment

by:Panda 5888
ID: 38717840
Thanks guys .. let me check and get back to you....
0
 

Author Comment

by:Panda 5888
ID: 38717864
Hi gaurav2rawat
No errors in repadmin /showreps /v
Under path HKLM\System\CurrentControlSet\Services\NTDS\Parameters, there were no #define DSA_WRITABLE_* entries
0
 

Author Comment

by:Panda 5888
ID: 38717867
Hi Venurajav, I only have 2 DC, they are replicating ... new user is replicated to another DC
0
 

Author Comment

by:Panda 5888
ID: 38717869
Hi gaurav2rawat ... it is not happening to all users, only a like 20/1000 users are having this problem..
0
 

Accepted Solution

by:
Panda 5888 earned 0 total points
ID: 38717894
Your suggestions lead me to "members of a protected group" direction ... then I found this http://support.microsoft.com/kb/907434 which is exactly describe my situation, after a little more investigation I found that all those involved are members of the Printer Operator, which is a protected group ... I've removed one of the user from Printer Operator, I will wait for 1-2 hrs before reseting his account with the correct permission, and then wait another 1-2 hrs to see if those permisson stays...
0
 

Author Comment

by:Panda 5888
ID: 38723019
when I remove the user from Printer operator group ... their permission stays, but once I put them back to Printer operator group, their permission goes missing again.

The missing permissions are "Send As right from the user and Allow inheritable permissions from parent to propagate to this object check box no longer selected."
0
 
LVL 56

Expert Comment

by:McKnife
ID: 38723066
Yes. That's expected behavior as you could read in the articles me and others have linked. The MS article you linked offers a best practice and a workaround. Any questions left?
0
 

Author Closing Comment

by:Panda 5888
ID: 38743261
working solution
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question