Re: OU Acling

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Something else to look out for. You can delete an object if you get either
one of these permissions:
DELETE on the object itself
or
DELETE_CHILD on the parent

So, even if you deny delete, but still allow to delete_child, then you'll be
able to delete still.

BTW, denying admins anything is sort of pointless. It might prevent
accidental deletion, but if they want to do something, they'll grant
themselves the right, and do it anyway.

--
Dmitri Gavrilov
SDE, DS Admin eXperience

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

"Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx> wrote in message
news:1120742036.517297@xxxxxxxxxxxxxxxxxxxxxx
>> shouldnt Deny over ride all permissions no matter what it is?
>
> Not necessarily. The order is as follows:
>
> -- explicit deny
> -- explicit allow
> -- inherited deny
> -- inherited allow.
>
>
> Also, does the EA or the administrators group own the container in
> question?
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>


.



Relevant Pages

  • Re: 70-290, properly answering access permission questions
    ... Maybe this is not something covered in the core exams. ... Inherited Deny permissions do not prevent access to an object if the ...
    (microsoft.public.cert.exam.mcse)
  • Re: Permissions inherited..from where?
    ... In AD and Explicit Allow with override and Inherited Deny but only on the level that it is set. ... Doesn't the Windows security model always apply explicit "deny" over "allow", ... Also, I remember granting an admin account permissions on single mailboxes and full stores, but it was never allowed to access them before removing the inherited "deny". ...
    (microsoft.public.exchange2000.admin)
  • Re: New article: How to change permissions on your mailbox store:
    ... "After you have made this change, you may still see unavailable Deny and ... Allow permissions assigned to your account. ... explicitly granted permissions override inherited permissions. ... As an explicit DENY overrides any ...
    (microsoft.public.windows.server.sbs)
  • Re: Share Permissions: Deny behaviour
    ... So how does Deny work on NTFS permissions? ... If you are talking about explicit Deny, ... I don't understand the DENY behaviour. ...
    (microsoft.public.windows.server.general)
  • Re: Permissions Question
    ... Keep in mind than an explicit allow will override an inherited deny, ... is possible to configure permissions that way where the inherited deny box ... It overrides any other permission. ...
    (microsoft.public.win2000.security)