Active Directory Security Group has permissions but group member does not

dgloveruk
dgloveruk used Ask the Experts™
on
Hi all,

I'm fairly new to Active Directory Administration so I apologise if I'm missing something fundamental.

I have written a program in VB.Net which takes an image from an email, converts it into a Byte String, and puts it in to the sending user's ThumbnailPhoto attribute in Active Directory. I know that the program works when I run it as a console application, but does not run as a service when I specify LDAP credentials.

I have created a user in Active Directory which is how I am authenticating the DirectorySearcher and DirectoryEntry LDAP requests in my program. This user is a member of the Universal Security Group PhotoEditors.

I have successfully Delegated Access to this security group to be able to Read and Write the ThumbnailPhoto attribute within our Users Organisational Unit. This has successfully applied to our users and sub-objects within that OU. Images below.

 Permissions on the O-Users group. PhotoEditors security group has the permissions applied.
 Permissions on one of our accounts which shows inheritance working.
However, at some point in the past inheritance has been disabled on some of our user accounts. I manually added the group to the 10 or so users that had inheritance disabled.

About an hour later I noticed that this group no longer had Security permissions on the users that had inheritance disabled. After some research I came across AdminSDHolder which appeared to be removing the security group. I then added the security group PhotoEditors to the AdminSDHolder entry and gave it Read and Write permissions to the ThumbnailPhoto attribute. This fixed the issue and now the PhotoEditors group has the correct permissions listed in the Security tab across all users. The image below shows a user that has inheritance disabled which also has the permission applied correctly by AdminSDHolder (since I did not add this permission manually).

User account that has the permission applied from AdminSDHolder
This so far is working as I understand. The problem I am now encountering is when I go to Advanced Security properties on a user that is affected by AdminSDHolder, I can see the PhotoEditors group is there and has the correct permissions, but the user who is a member of that PhotoEditors group does not have the Write ThumbnailPhoto permission. I checked this under Properties - Security - Advanced - Effective Permissions, and entered the name of the user who is in the PhotoEditors group. Screenshot below.

Effective Permissions
The "My Photo" user is the only member of the Security Group PhotoEditors. It is my understanding that you create a security group, assign the required permissions to that security group, then add the users to the security group that you want to have that permission. But there appears to be something overriding the permissions that the user has, even though the group it's a member of has permissions.

I would be very grateful if anyone can shed any light on this, as it's been plaguing me in one form or another for the past week.

Many thanks :)
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Chris DentPowerShell Developer
Top Expert 2010

Commented:
Your images show the right being applied to child user objects. Is the right on AdminSDHolder similarly configured? if so, it needs to apply to the current object, the ACL is copied from AdminSDHolder by the propagator, not applied as if objects were children.

Author

Commented:
Hi Chris,

Thanks for your quick reply.

I'm running Windows Server 2008 R2 Standard, and the permission entry is below:

PermissionEntryForAdminSDHolder.png
Sorry for the stupid question but where would I apply this permission to the current object?
Chris DentPowerShell Developer
Top Expert 2010

Commented:
Change the "apply to" drop down to include (or only be) the current object. At the moment it cannot apply because that right set on a user object will not apply to the user object. That works just fine in the context where you apply the right to an OU (to affect descendant objects).
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Hi Chris,

When I change the "Apply to:" drop down to be "This object only", I cannot find the Write ThumbnailPhoto entry listed. Is there something that I am missing?

"This Object Only" does not show the Write thumbnailPhoto attribute
Many thanks,

David
Chris DentPowerShell Developer
Top Expert 2010
Commented:
That's annoying, is there an object that applies to this object and descendants?

It may be possible to set the permission properly outside of the GUI, it's limiting the choices because of the current object type (SDAdminHolder isn't a user).

Otherwise, see if there's anything in the Object tab that'll let you expand the selection. I'm afraid I haven't got an AD domain here to give you really clear directions.
Hi Chris,

I couldn't see anything in the Objects tab that did what I need - in there is all of the Create objects permissions from what I could tell.

I used DSACLS and ran the following command:

dsacls "CN=AdminSDHolder,CN=System,DC=DOMAIN" /G FGDOM1\PhotoEditors:RPWP;thumbnailPhoto

Open in new window


which seemed to apply the PhotoEditors group Read and Write thumbnailPhoto attribute permissions to This object only (image below).

New permission added after DSACLS was run
I will check this later today to see if it has applied across the domain correctly. Many thanks for all of your help Chris :)

Author

Commented:
Command has granted correct permissions. As Chris pointed out, it needed to be done from the command-line (i.e. not the GUI), and the permission needed to be set as if it were being applied to the user.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial