Unable to delegate CONTROL permissions to hidden attribute (server 2003)


hello

i following https://support.microsoft.com/en-us/kb/922836

i trying delegate control permissions; below

how let non-administrative users see attribute data

note following procedures   require   use ldp.exe tool included windows server 2003 r2 active   directory application mode (adam). other versions of ldp.exe tool cannot   set permissions.

how manually set control_access permissions on user account

  1. open ldp.exe tool included windows server 2003 r2 adam.
  2. connect , bind directory.
  3. select user account, right-click account, click advanced, click security descriptor, , click ok.
  4. in dacl box, click add ace.
  5. in trustee box, type group name or user name want grant permissions.
  6. in control access box, verify changes made in step 5.

i have tried using version of ldp installed server 2003 r2; , have downloaded , installed adam https://www.microsoft.com/en-us/download/confirmation.aspx?id=4201

this version of ldp appears same version using (version 3)

for step 4 there no dacl box

is there means of doing this? if run through delegation of control account, can see 'read' , 'write' permissions attribute want see. no control however

appreciate assistance in advance

i cottoned onto referring , you've misunderstood instruction.

here's different explanation:

  1. open ldp.
  2. connect , bind ad ds service would.
  3. select view menu/tree.
  4. drop down list , choose cn=schema,cn=configuration,dc=yourdomain,dc=com.
  5. expand "cn=schema,cn=configuration,dc=yourdomain,dc=com".
  6. right-click attribute want set searchflags value , choose advanced/security descriptor.
  7. click ok button in confirmation screen. there no dacl checkbox here default option.
  8. proceed edit dacl in subsequent screen. have manually click existing acl list entry "add ace" button light up. that's age-old minor issue editor.

cheers,
lain



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...