Re: trouble with delegating unlock rights



"" wrote:
> I am trying to delegate account unlock rights as per KB294952
> with no
> success. When the users review a locked account the unlock box
> is still
> grayed out. I have modified the Dssec.dat file on the
> workstations
> being used and have included a dump from DSACLS on object. Any
> help
> would be appreciated.
>
> Thanks
> Joe
>
> Access list:
> Effective Permissions on this object are:
> Allow NT AUTHORITYSYSTEM FULL
> CONTROL
> Allow COFCUDomain Admins FULL
> CONTROL
> Allow NT AUTHORITYAuthenticated Users SPECIAL
> ACCESS
> READ
> PERMISSONS
> LIST
> CONTENTS
> READ
> PROPERTY
> LIST
> OBJECT
> Allow COFCUUser1 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUUser2 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUIT Domain Administrators FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1394 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1397 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUCOMPUTER7$ FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1454 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1455 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1476 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1461 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUCOMPUTER5$ FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1390 FULL
> CONTROL
> <Inherited from parent>
> Allow BUILTINAdministrators SPECIAL
> ACCESS
> <Inherited from parent>
> DELETE
> READ
> PERMISSONS
> WRITE
> PERMISSIONS
> CHANGE
> OWNERSHIP
> CREATE
> CHILD
> LIST
> CONTENTS
> WRITE
> SELF
> WRITE
> PROPERTY
> READ
> PROPERTY
> LIST
> OBJECT
> CONTROL
> ACCESS
> Allow COFCUEnterprise Admins FULL
> CONTROL
> <Inherited from parent>
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS
> <Inherited from parent>
> LIST
> CONTENTS
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS
> <Inherited from parent>
> LIST
> CONTENTS
> Allow BUILTINAccount Operators SPECIAL
> ACCESS for
> computer
> CREATE
> CHILD
> DELETE
> CHILD
> Allow BUILTINAccount Operators SPECIAL
> ACCESS for
> user
> CREATE
> CHILD
> DELETE
> CHILD
> Allow BUILTINAccount Operators SPECIAL
> ACCESS for
> group
> CREATE
> CHILD
> DELETE
> CHILD
> Allow BUILTINPrint Operators SPECIAL
> ACCESS for
> printQueue
> CREATE
> CHILD
> DELETE
> CHILD
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> computer <Inherited from parent>
> CREATE
> CHILD
> Allow COFCUUser1 SPECIAL
> ACCESS for
> computer <Inherited from parent>
> CREATE
> CHILD
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> gPOptions <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> gPLink <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser1 SPECIAL
> ACCESS for
> gPOptions <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser1 SPECIAL
> ACCESS for
> gPLink <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> Public Information <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> Personal Information <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> groupType <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> displayName <Inherited from parent>
> WRITE
> PROPERTY
>
> Permissions inherited to subobjects are:
> Inherited to all subobjects
> Allow COFCUUser2 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUUser1 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUIT Domain Administrators FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1394 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1397 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUCOMPUTER7$ FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1454 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1455 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1476 FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1461 FULL
> CONTROL
> <Inherited from parent>
> Allow COFCUCOMPUTER5$ FULL
> CONTROL
> <Inherited from parent>
> Allow S-1-5-21-1659004503-1220945662-839522115-1390 FULL
> CONTROL
> <Inherited from parent>
> Allow BUILTINAdministrators SPECIAL
> ACCESS
> <Inherited from parent>
> DELETE
> READ
> PERMISSONS
> WRITE
> PERMISSIONS
> CHANGE
> OWNERSHIP
> CREATE
> CHILD
> LIST
> CONTENTS
> WRITE
> SELF
> WRITE
> PROPERTY
> READ
> PROPERTY
> LIST
> OBJECT
> CONTROL
> ACCESS
> Allow COFCUEnterprise Admins FULL
> CONTROL
> <Inherited from parent>
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS
> <Inherited from parent>
> LIST
> CONTENTS
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS
> <Inherited from parent>
> LIST
> CONTENTS
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> computer <Inherited from parent>
> CREATE
> CHILD
> Allow COFCUUser1 SPECIAL
> ACCESS for
> computer <Inherited from parent>
> CREATE
> CHILD
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> gPOptions <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUIT Domain Administrators SPECIAL
> ACCESS for
> gPLink <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser1 SPECIAL
> ACCESS for
> gPOptions <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser1 SPECIAL
> ACCESS for
> gPLink <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> Public Information <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> Personal Information <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> groupType <Inherited from parent>
> WRITE
> PROPERTY
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS for
> displayName <Inherited from parent>
> WRITE
> PROPERTY
>
> Inherited to group
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS
> <Inherited from parent>
> READ
> PERMISSONS
> WRITE
> PERMISSIONS
> LIST
> CONTENTS
> READ
> PROPERTY
> LIST
> OBJECT
> Inherited to user
> Allow COFCUExchange Enterprise Servers SPECIAL
> ACCESS
> <Inherited from parent>
> READ
> PERMISSONS
> LIST
> CONTENTS
> READ
> PROPERTY
> LIST
> OBJECT
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS
> <Inherited from parent>
> READ
> PERMISSONS
> LIST
> CONTENTS
> READ
> PROPERTY
> LIST
> OBJECT
> Inherited to group
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS
> <Inherited from parent>
> READ
> PERMISSONS
> LIST
> CONTENTS
> READ
> PROPERTY
> LIST
> OBJECT
> Inherited to user
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS for
> Logon Information <Inherited from parent>
> READ
> PROPERTY
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS for
> Account Restrictions <Inherited from parent>
> READ
> PROPERTY
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS for
> Group Membership <Inherited from parent>
> READ
> PROPERTY
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS for
> General Information <Inherited from parent>
> READ
> PROPERTY
> Allow BUILTINPre-Windows 2000 Compatible Access SPECIAL
> ACCESS for
> Remote Access Information <Inherited from parent>
> READ
> PROPERTY
> Allow COFCUHelp_Desk SPECIAL
> ACCESS for
> lockoutTime <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser3 SPECIAL
> ACCESS for
> lockoutTime <Inherited from parent>
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUHelp_Desk SPECIAL
> ACCESS for
> lockoutTime
> WRITE
> PROPERTY
> READ
> PROPERTY
> Allow COFCUUser3 SPECIAL
> ACCESS for
> lockoutTime
> WRITE
> PROPERTY
> READ
> PROPERTY
> The command completed successfully

Both http://support.microsoft.com/?id=294952 and
http://support.microsoft.com/?id=279723 should guide you how to do
this. It works for me!
However, why are the SIDs shown instead of the user/group names? Have
those users/groups been deleted?
Maybe a stupid remark, but did you assign the permissions to the
correct OU?

To see if it is correct check the permissions on the OU where you
delegated the permissions.

It should state
Type = ALLOW
Name = <group> or <user>
Permission = Read/Write Property (Read LockOutTime and Write
LockOutTime)
Inherited from = <not inherited>
Apply to = User Objects

The user objects you are trying to unlock should have permission
inheritance enabled

--
Posted using the http://www.windowsforumz.com interface, at author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.windowsforumz.com/Active-Directory-trouble-delegating-unlock-rights-ftopict419246.html
Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.windowsforumz.com/eform.php?p=1400215
.



Relevant Pages

  • Re: ADAM And ACLs
    ... The ACLs for the OU which is the parent of the object below are: ... Effective Permissions on this object are: ... SPECIAL ACCESS ... for the naming context and is usually present by inheritance, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions Question
    ... Also, there's usually no good reason, to grant your users Full Control on ... any folder => instead it should be sufficient to grant them Modify ... the inherited read permissions from the root will not prevent your users ... to change stuff on C (inheritance is "additive" - it get's somewhat more ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions
    ... tab, add a user, change the permissions, the user doesn't get propagated ... are adding the permissions and the child folders too? ... structure, any user you add at a parent level, any level, will propagate ... not change the grayed-out one unless you uncheck allow inheritance. ...
    (microsoft.public.windows.server.general)
  • Re: User Permissions Issues
    ... permissions for that folder are not inherited from the parent by default all ... Inheritance is the default IF you use normal tools/procedures ... to create the parent directory permissions. ...
    (microsoft.public.win2000.security)
  • Re: User Permissions Issues
    ... > I have checked the permissions on the parent folder and all seems correct. ... Maybe inheritance is disabled at an intermediate ...
    (microsoft.public.win2000.security)