Unable to delegate CONTROL permissions to hidden attribute (server 2003)
hello
i following https://support.microsoft.com/en-us/kb/922836
i trying delegate control permissions; below
how let non-administrative users see attribute data
note following procedures require use ldp.exe tool included windows server 2003 r2 active directory application mode (adam). other versions of ldp.exe tool cannot set permissions.how manually set control_access permissions on user account
- open ldp.exe tool included windows server 2003 r2 adam.
- connect , bind directory.
- select user account, right-click account, click advanced, click security descriptor, , click ok.
- in dacl box, click add ace.
- in trustee box, type group name or user name want grant permissions.
- in control access box, verify changes made in step 5.
i have tried using version of ldp installed server 2003 r2; , have downloaded , installed adam https://www.microsoft.com/en-us/download/confirmation.aspx?id=4201
this version of ldp appears same version using (version 3)
for step 4 there no dacl box
is there means of doing this? if run through delegation of control account, can see 'read' , 'write' permissions attribute want see. no control however
appreciate assistance in advance
i cottoned onto referring , you've misunderstood instruction.
here's different explanation:
- open ldp.
- connect , bind ad ds service would.
- select view menu/tree.
- drop down list , choose cn=schema,cn=configuration,dc=yourdomain,dc=com.
- expand "cn=schema,cn=configuration,dc=yourdomain,dc=com".
- right-click attribute want set searchflags value , choose advanced/security descriptor.
- click ok button in confirmation screen. there no dacl checkbox here default option.
- proceed edit dacl in subsequent screen. have manually click existing acl list entry "add ace" button light up. that's age-old minor issue editor.
cheers,
lain
Windows Server > Windows Server General Forum
Comments
Post a Comment