Re: Win2k - Account Operator not working properly



The tool is a command line tool from Microsoft to enumerate the permissions on an object. It is much better than using the GUI because the GUI won't always display what is actually there. Also I wrote a vbscript for the refresh work I did on O'Reilly Active Directory Third Edition that does similar work but gives even more info on the security descriptors.

DSACLS can both read and set permissions. It is part of the support tools offering. The latest version of DSACLS can be gotten from K3 SP1 or the ADAM install from the R2 Beta.



--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


thawkz wrote:
I am not familiar with DSACLS dump.....what will that do for us? I suspect by the name of the process, it will show the ACL list for a given object....just curious, if after using the utility, there appear to be problems with the permissions being applied to the object, how can it be corrected? Does DSACLS have the ability to fix problems as well as identify them?

Thanks.

"Joe Richards [MVP]" wrote:


Post a DSACLS dump of an OU of concern and what isn't happening in that OU that you expect should happen.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


thawkz wrote:

....let me also add some details to my most recent post--we have multi-level OUs....
I delegated control to Helpdesk group in the top level OU.....So, currently:
Helpdesk CAN modify/reset/create/delete accounts in the top-level OU.
Helpdesk CAN create new accounts/modify/delete/reset passwords for NEW accounts in OUs beneath the top-level OU.
Helpdesk CANNOT modify/reset existing accounts in the OUs beneath the top-level OU.
Please feedback comments/questions......thanks for your help.



"thawkz" wrote:



Good enough.....One followup question......I used the delegate control wizard to grant the required permissions for the HelpDesk group. The members of the group can now create/delete/modify NEW user accounts and reset passwords for these accounts, but cannot create/delete/modify/reset passwords for any accounts that existed PRIOR to my running the delegate control wizard.....any ideas on a cause and a fix?
Thanks.


"Joe Richards [MVP]" wrote:



You shouldn't use acc ops because there are side effects that tend to mess people up (see adminsdholder functionality) plus it was put there simply as a holdover from NT.

The proper way to handle this is to create one or more groups and delegate the permissions needed to those groups and add admins to the groups as needed.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


thawkz wrote:


Running (an inherited) Windows 2000 Active Directory.
Helpdesk staff needed permissions to manage user account/reset passwds, etc.
Added Helpdesk staff users to Account Operators built-in group.
Helpdesk staff still not able to manage user accounts/passwords, etc.
Used the Delegate Control wizard as workaround...... but I would like to fix the issue with Account Operators--how can I make the sure the Account Operators built-in group has all of the required permissions? What settings do I check and where? (I suspect some of the default permissions for the Account Operators group have been modified, but I have no idea which ones....).
Thanks.



.



Relevant Pages

  • Windows 2003 R2 delegated permissions are not available for some users in an OU
    ... The group HelpDesk has four IT ... When I look at my Users Accounts OU, ... for all members shows the HelpDesk having special permissions - EXCEPT ...
    (microsoft.public.windows.server.security)
  • Re: Win2k - Account Operator not working properly
    ... Helpdesk CAN create new accounts/modify/delete/reset passwords for NEW accounts in OUs beneath the top-level OU. ... The members of the group can now create/delete/modify NEW user accounts and reset passwords for these accounts, but cannot create/delete/modify/reset passwords for any accounts that existed PRIOR to my running the delegate control wizard.....any ideas on a cause and a fix? ... The proper way to handle this is to create one or more groups and delegate the permissions needed to those groups and add admins to the groups as needed. ...
    (microsoft.public.windows.server.active_directory)
  • Re: OU delegation, permission to move but not delete objects
    ... Has anyone tried limiting a group's permissions, say the helpdesk, to only be allowed to create and modify user/computer accounts in a particular OU and sub-OUs, but NOT delete any accounts? ... If you've locked it down like this, can the helpdesk still move accounts between sub OUs? ... I'm checking to see if anyone else has experience/advice before I start researching and experimenting. ...
    (microsoft.public.windows.server.active_directory)
  • OU delegation, permission to move but not delete objects
    ... Has anyone tried limiting a group's permissions, say the helpdesk, to only ... be allowed to create and modify user/computer accounts in a particular OU ... see if anyone else has experience/advice before I start researching and ...
    (microsoft.public.windows.server.active_directory)
  • Re: File Sharing (again - sorry, Pd)
    ... InTerminal, type umask. ... Back in the good old days, Mac OS X user accounts ... The reason that the file permissions are "resetting" each time the ... that folder inherit the ACLs from the folder. ...
    (uk.comp.sys.mac)