Re: Security Group Keeps getting removed???



I think I got your meaning now on the second part. Tell me if I am right;
The email_enabled_accountX is a member of Domain Admins, but the users in the
group I am adding are NOT members of Domain admins, so they get removed?

"Jorge Silva" wrote:

Hi
Every hour, the Windows domain controller that holds the primary domain
controller (PDC) Flexible Single Master Operation (FSMO) role compares the
ACL on all security principals (users, groups, and machine accounts) present
for its domain in Active Directory. If the ACL is different, the ACL on the
user object is overwritten to reflect the security settings of the
AdminSDHolder object (which includes disabling ACL inheritance). This
protects these administrative accounts from being modified by unauthorized
users if the accounts are moved to a container or organizational unit in
which a user has been delegated administrative privilege for the
modification of user accounts. Note that when a user is removed from the
administrative group, the process is not reversed and must be manually
changed

Description and Update of the Active Directory AdminSDHolder Object

http://support.microsoft.com/?id=232199
AdminSDHolder Thread Affects Transitive Members of Distribution Groups
http://support.microsoft.com/?id=318180
The "Send As" right is removed from a user object after you configure the
"Send As" right in the Active Directory Users and Computers snap-in in
Exchange Server

http://support.microsoft.com/kb/907434

Delegated permissions are not available and inheritance is automatically
disabled
http://support.microsoft.com/?id=817433
AdminSDHolder Object Affects Delegation of Control for Past Administrator
Accounts
http://support.microsoft.com/?id=306398



--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Space Junk" <SpaceJunk@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C4B735E6-1737-424E-A1EC-752F09C53504@xxxxxxxxxxxxxxxx
Here is my issue, email_enabled_accountX has a security_groupY applied to
it
with "Send As" permissions. There are 12 other domain controllers,
accessing
each one manually and checking confirms the replication of this change.
However, after an hour or so, the security_groupY is no longer in the ACL
for
email_enabled_accountX, we are doing the same thing with
email_enabled_accountZ and never have this problem. email_enabled_accountX
is not inheritating any permissions.

This is not being done by a human, so what else could possible be doing
this?



.



Relevant Pages

  • Re: Security Group Keeps getting removed???
    ... ACL on all security principals (users, groups, and machine accounts) present ... Delegated permissions are not available and inheritance is automatically ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security Group Keeps getting removed???
    ... overwritten to reflect the security settings of the AdminSDHolder object ... accounts are moved to a container or organizational unit in which a user has ... If the security descriptor for a member of the protected groups doesn't ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need AD HELP - "Active Directory" "user object" lost "Allow Inheritable" check problem
    ... ACL on all security principals (users, groups, and machine accounts) present ... Description and Update of the Active Directory AdminSDHolder Object ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account Operators accessing other account operators
    ... Once you are done with that you should move to fully delegated accounts where the exact permissions needed are delegated. ... group and delegate the correct permissions on an OU that applies to the correct objects in that OU. ... the Microsoft Windows domain controller that has the primary domain controller emulator operations master role verifies the ACLs on members of these administrative groups and compares them to the ACL on the AdminSDHolder object. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admins and Anonymous Logon Group
    ... ACL on all security principals (users, groups, and machine accounts) present ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)