Re: Security Group Keeps getting removed???



check if they're members of the protected groups that I mentioned in
previous post

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Space Junk" <SpaceJunk@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:1F86A5B7-1211-4024-8599-68ED41CBE764@xxxxxxxxxxxxxxxx
I think I got your meaning now on the second part. Tell me if I am right;
The email_enabled_accountX is a member of Domain Admins, but the users in
the
group I am adding are NOT members of Domain admins, so they get removed?

"Jorge Silva" wrote:

Hi
Every hour, the Windows domain controller that holds the primary domain
controller (PDC) Flexible Single Master Operation (FSMO) role compares
the
ACL on all security principals (users, groups, and machine accounts)
present
for its domain in Active Directory. If the ACL is different, the ACL on
the
user object is overwritten to reflect the security settings of the
AdminSDHolder object (which includes disabling ACL inheritance). This
protects these administrative accounts from being modified by
unauthorized
users if the accounts are moved to a container or organizational unit in
which a user has been delegated administrative privilege for the
modification of user accounts. Note that when a user is removed from the
administrative group, the process is not reversed and must be manually
changed

Description and Update of the Active Directory AdminSDHolder Object

http://support.microsoft.com/?id=232199
AdminSDHolder Thread Affects Transitive Members of Distribution Groups
http://support.microsoft.com/?id=318180
The "Send As" right is removed from a user object after you configure the
"Send As" right in the Active Directory Users and Computers snap-in in
Exchange Server

http://support.microsoft.com/kb/907434

Delegated permissions are not available and inheritance is automatically
disabled
http://support.microsoft.com/?id=817433
AdminSDHolder Object Affects Delegation of Control for Past Administrator
Accounts
http://support.microsoft.com/?id=306398



--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Space Junk" <SpaceJunk@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C4B735E6-1737-424E-A1EC-752F09C53504@xxxxxxxxxxxxxxxx
Here is my issue, email_enabled_accountX has a security_groupY applied
to
it
with "Send As" permissions. There are 12 other domain controllers,
accessing
each one manually and checking confirms the replication of this change.
However, after an hour or so, the security_groupY is no longer in the
ACL
for
email_enabled_accountX, we are doing the same thing with
email_enabled_accountZ and never have this problem.
email_enabled_accountX
is not inheritating any permissions.

This is not being done by a human, so what else could possible be doing
this?





.



Relevant Pages

  • Re: Security Group Keeps getting removed???
    ... ACL on all security principals (users, groups, and machine accounts) present ... Description and Update of the Active Directory AdminSDHolder Object ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security Group Keeps getting removed???
    ... overwritten to reflect the security settings of the AdminSDHolder object ... accounts are moved to a container or organizational unit in which a user has ... If the security descriptor for a member of the protected groups doesn't ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need AD HELP - "Active Directory" "user object" lost "Allow Inheritable" check problem
    ... ACL on all security principals (users, groups, and machine accounts) present ... Description and Update of the Active Directory AdminSDHolder Object ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Re: I need a permission GURU!
    ... If the only members of the group are limited user ... Why not just create a new group, and stick the accounts ... Then use the Deny ACE ... >> resource, so when an Administrator hits it, the access ...
    (microsoft.public.windowsxp.security_admin)
  • I need a permission GURU!
    ... the Administrator and Power Users would fall ... Hence you're specifically putting a Deny ACE on the ... >on a file or folder in either OS to lock out members of ... >Its as if all accounts fall under the "users" group. ...
    (microsoft.public.windowsxp.security_admin)

Loading