Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Default User object security

Reply
Thread Tools Display Modes

Default User object security

 
 
2010
Guest
Posts: n/a

 
      11-24-2009
Windows 2003 SP2

I am trying to fix a problem where delegation of control is not working
properly to usr OUs. I ca't seem to keep permissions on user account objects
that allow user accounts to be moved between OUs. I think it may be related
to protected account membership on the user objects themselves. ALso the
"inherit permissions from parent" is unchecked on user objects. Certain user
new user objects work fine and are inheriting. What are the default security
to use on user objects so that i can remvoe membership from protected groups
and how should I allow inherit permissions from OU container so i can delgate
permisions.?
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      11-24-2009
Hello 2010,

Please describe in detail what you have configured in delegate control, so
we can reproduce your problem.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Windows 2003 SP2
>
> I am trying to fix a problem where delegation of control is not
> working properly to usr OUs. I ca't seem to keep permissions on user
> account objects that allow user accounts to be moved between OUs. I
> think it may be related to protected account membership on the user
> objects themselves. ALso the "inherit permissions from parent" is
> unchecked on user objects. Certain user new user objects work fine
> and are inheriting. What are the default security to use on user
> objects so that i can remvoe membership from protected groups and how
> should I allow inherit permissions from OU container so i can delgate
> permisions.?
>



 
Reply With Quote
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      11-25-2009
Sounds like you understand that protected groups are causing the inherit
flag to be unchecked.
http://technet.microsoft.com/en-us/m...minholder.aspx

What you haven't defined is what you want the users who are in protected
groups to be able to do once they have been removed from these groups. It
really is not possible to tell you what the specific permissions a protected
group has. Just define what you need users to be able to do and I believe
the folks monitoing this NewsGroup will be able to guide you through it.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"2010" <> wrote in message
news:80E4E1BB-AED5-468A-8931-...
> Windows 2003 SP2
>
> I am trying to fix a problem where delegation of control is not working
> properly to usr OUs. I ca't seem to keep permissions on user account
> objects
> that allow user accounts to be moved between OUs. I think it may be
> related
> to protected account membership on the user objects themselves. ALso the
> "inherit permissions from parent" is unchecked on user objects. Certain
> user
> new user objects work fine and are inheriting. What are the default
> security
> to use on user objects so that i can remvoe membership from protected
> groups
> and how should I allow inherit permissions from OU container so i can
> delgate
> permisions.?



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Move \Users folder once for all Peter Meinl Windows Vista Installation 25 03-03-2010 02:37 AM
Repair DNS 4010 events... Jake Windows Server 1 11-04-2009 11:20 AM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 07:02 PM
Files on D: from XP have strange user under Security. Trond Windows Vista Administration 0 02-25-2007 01:49 AM
ActiveSync 4.1, Calendar and "Processing" Dale Reeck ActiveSync 10 12-20-2005 01:44 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59