AdminSDHolder thread - How can I block??



Is there any to block the update or refresh generated by the
AdminSDHolder thread from being applied to an individual user in one of
the protected groups? For example, a user who's a domain admin (User1)
wishes to grant another user (User2) "send as" permissions on his
mailbox. Every hour or so User2 "disappears" from the security tab of
User1 in effective removed from the ACL of User1. The options seem to
be to add "send as" permissions for User2 to the AdminSDHolder
container (I've tried this on my testbed but haven't quite got it to
work even though the user permissions did "trickle down" to the groups
and users) or remove the user from the domain admins groups and reset
the admin count attribute. What I really want to do is just "block"
changes for this one particular user, without affecting how
AdminSDHolder is being applied to other groups and users. Possible or
not? TIA

-Jim

.



Relevant Pages

  • Re: AdminSDHolder thread - How can I block??
    ... a user who's a domain admin ... > wishes to grant another user (User2) "send as" permissions on his ... > User1 in effective removed from the ACL of User1. ... > be to add "send as" permissions for User2 to the AdminSDHolder ...
    (microsoft.public.win2000.active_directory)
  • Re: Security question regarding directory and file permissions
    ... > is done by design. ... > user1, I create a file called testfile in that directory. ... > log in as user2, change to the test directory, and edit the file using ... I thought that file permissions would ...
    (comp.os.linux.security)
  • Security question regarding directory and file permissions
    ... RedHat 8 and RedHat 9 systems, but not on AIX or Solaris) is a bug or ... I create a directory called /test with permissions of 777. ... has permissions of 664, owner is user1, and group is user1. ... but is now owned by user2 with a group of user2. ...
    (comp.os.linux.security)
  • Re: /proc filesystem allows bypassing directory permissions on Linux
    ... || User1 creates file with permissions 0644 ... || hard link after the sysadmin checked, but before the permissions were ... User2 opens file for read access on file descriptor 4 ... User1 verifies no hard links to file ...
    (Bugtraq)
  • Re: Prevent changes to Administrator password
    ... you need to understand that permissions on the RootDomain\Administrator account are applied via AdminSDHolder so you need to modify the permissions on the AdminSDHolder object in the root domain. ... If you are just having him create a group and modify it using ACLs then if anything goes wrong it can easily be undone by removing the admins from the new group, ... Deny the Restricted Admins group the Write Permissions permission ...
    (microsoft.public.windows.server.active_directory)

Loading