RE: Determining query rights.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: gordonah (gordonah_at_discussions.microsoft.com)
Date: 12/01/04


Date: Wed, 1 Dec 2004 04:29:01 -0800

WS

further to Glenn's answer, you can check the rights an object has over the
domain using the effective rights tool.
If in AD Users and Computers (must be W2K3 version) you right-click on
domain and select Properties, Security, Advanced, Effective Permissions, you
can then choose an object and determine it's permission from the domain
downwards (assuming nothing interferes with standard hierarchial inheritance).
To query objects I think the rights List contents, Read all properties and
Read permissions are required, as per membership of the Pre-W2K compatible
group.
These are quite extensive rights over a whole domain, but can be set for
particular OU structures or object types only.

Gordon

"WS" wrote:

> I've been asked to check that a particular account in AD can query AD
> itself. How can I determine this, and if it cannot query, then how do you
> give it permissions to do so?
>
> Thanks.
>
>
>
>



Relevant Pages

  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... Restricted Admins group to mitigate against what you propose Deji. ... also need to make sure the DAs in question cannot elevate their rights to EA, ... > By adding the Deny Write Permissions ACE, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > By adding the Deny Write Permissions ACE, ... > permission to modify the ACL on AdminSDHolder. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Why is Fedora not a Free GNU/Linux distributions?
    ... Taking away legitimate rights, yes, that would be immoral. ... specifically to be incompatible with the GPL, ... Software license) doesn't take away any right you had. ... There are other permissions that enable you to copy and distribute the ...
    (Fedora)
  • Re: Prevent changes to Administrator password
    ... Have you thought about delegating the exact permissions needed instead of using DA or restructing your forest? ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > Restricted Admins group to mitigate against what you propose Deji. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... * This posting is provided "AS IS" with no warranties and confers no rights! ... his/her account from the Restricted Admin group and clears the flag? ... > By adding the Deny Write Permissions ACE, ... > permission to modify the ACL on AdminSDHolder. ...
    (microsoft.public.windows.server.active_directory)