Some user and group objects stop inheriting permissions from parent on a seemingly random basis


wondering if has come across issue before.

recently, 1 of administrators @ site working on reported unable add user group - should not have been case (these administrators have been granted permissions @ domain level manage group memberships).  when looked @ group in question discovered "inherit permissions parent" box unchecked - should not case in environment.  simple matter reverse this, , fixed issue @ stage.  on following weeks however, further groups , users appeared in state - causing administrators bit of headache.

i responded running dsacls command against group , user objects in domain force permissions inherit, , seemed resolve issue.

however, have morning come across group showing behaviour (not inheriting permissions).  relatively (admittedly not 100%) 1 of same groups showed behaviour , amended (as were).

i (again, not 100%) not being configured rogue administrator, @ loss explain otherwise.  has seen behaviour before - if so, explanations/solutions?

this issue happening in 2 production environments - 1 2003 domain , other 2008 domain (both @ respective maximum forest/functional level, etc).


voice of shatner

this 1 of frustrating scenario's admin first time run across this.  normal, designed behavior result becuase of adminsdholder , protected groups.  there great article on link below, great job in explaining occuring , why.

http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx

 

--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
http://www.pbbergs.com    twitter @pbbergs

please no e-mails, questions should posted in newsgroup this
posting provided "as is" no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...