Link to home
Create AccountLog in
Active Directory

Active Directory

--

Questions

--

Followers

Top Experts

Avatar of creative555
creative555

Newer Security translation tools alike subinacl for Windows 10
Hello,
We are using subinacle for security translation of files. it is an old version and doesn't look that Microsoft updated this tool since 2012.

Does anyone know is there any newer tools available that do the same thing - Migrate security information about objects, replace the security information, etc


https://www.microsoft.com/en-us/download/details.aspx?id=23510

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of Michael PfisterMichael Pfister🇩🇪

The only alternative that I know about is SetACL (https://helgeklein.com/setacl/ but it seems ist as old as subinacl.

Never tried if you could achieve similar things with Windows PowerShell but I'd expect that you can replace subinacl with some scripting.

Avatar of McKnifeMcKnife🇩🇪

Please give an example of a command that does not work as expected with subinacl and name the OS Win10 version (10240, 1511, 1607?) that you are using, please.

Avatar of creative555creative555

ASKER

it is getting hung on Cortana translation in Windows 10. In particular, it gets hung on interactive user.


C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\a669bb36[1].js : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\ab445dca[1].js : new ace for testtarget\john.doe
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\ab445dca[1].js : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\appcache[1].man : new ace for testtarget\john.doe
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\appcache[1].man : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\container.dat : new ace for testtarget\john.doe
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\container.dat : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\d64c2fba[1].css : new ace for testtarget\john.doe
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\d64c2fba[1].css : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\Init[1].htm : new ace for testtarget\john.doe
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AC\AppCache\RZUQKOVI\4\Init[1].htm : 1 change(s)
C:\Users\john.doe\AppData\Local\Packages\Microsoft.Windows.

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


this is the anniversary edition Windows 10 14393 build

Avatar of serialbandserialband🇺🇦

I believe subinacl.exe was not updated because the built-in icacls.exe should do much of what it used to do and you don't have to go download it.

Avatar of McKnifeMcKnife🇩🇪

Please tell me the command itself. You only quoted the output of the command.

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Command line:
"C:\Windows\TEMP\SubInAcl.exe"  /outputlog="C:\Windows\TEMP\SubInACL.txt" /playfile "C:\Windows\TEMP\MSM-WMS\SubInACL_cmd.txt"

Let me know if this is it.

Avatar of McKnifeMcKnife🇩🇪

Look, still I cannot see what is inside the playfile, so it needs to be quoted as well.
Or better, give a simple example of something that fails.

Here you go. See attached. this is the log of subinacle that failed at Cortana for interactive user. This user was logged in. It is at the very end.
subinaclFailedonCortana.txt

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.


Let me know if you also want a successful Log were it didn't hang and finished. Like I said it is intermittent. Sometimes it works and sometimes it doesn't.

Do you know what is the best approach to organize this data into readable format so that I can understand what permissions are changed and were?


Once I know what and were we need to modify, then at least I know what script is needed.

 Also, need to learn what changes have been made to security in Win 10 so that the right script can be found that does security translation.

Please help.
thank you very much.

Avatar of McKnifeMcKnife🇩🇪

Again... please upload the playfile. It is C:\Windows\TEMP\MSM-WMS\SubInACL_cmd.txt

here it is
SubinACL_cmd.txt

Free T-shirt

Get a FREE t-shirt when you ask your first question.

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


ASKER CERTIFIED SOLUTION
Avatar of McKnifeMcKnife🇩🇪

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Hey McKnife, you are the best!! thank you so much! I didn't know you could generate playfile! I used the existing subinacle_cmd and it worked because it was on the same computer. But now with your help I was able to generate a new playfile and test it a different way.

So, I ran it and it failed on Cortana step as well.

Could you please check out my other related question that I just opened. Thank you again.
Active Directory

Active Directory

--

Questions

--

Followers

Top Experts

Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.