Re: User security settings lost



Thanks for your reply Anthony.

It' anyway very strange because I'm a Domain Admin and the accounts I'm
trying to modify are Domain Users, so at a lower privilege level.
Is there any workaroud ?

Thanks.

--
Massimo

"Anthony" <nospam@xxxxxxxx> ha scritto nel messaggio
news:eXwWF5ZNIHA.3916@xxxxxxxxxxxxxxxxxxxxxxx
Hi Massimo,
This is AdminSDHolder at work. It prevents people hijacking an account
with equal or greater privileges in AD.
Anthony, http://www.airdesk.com

<mpiceni@xxxxxxxxxxxxxxxx> wrote in message
news:uXwtkGZNIHA.1208@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I've an active directory with 2 Windows Server 2003 SP2 domain
controllers. Probably after the Exchange 2003 SP2 installation (but I'm
not so sure), I experience a strange problem on user objects in Active
directory. If I change some security settings on any user, after few
hours the settings get reset to their original value. Even if I flag the
"Allow inheritable permissions from the parent to propagate to this
object...", I'll find it cleared after a while (with the inherited
pemissions lost).
I couldn't get any help from MS KB.
Anyone has ever experienced this problem ? Any solution ?

Thanks.

--
Massimo





.



Relevant Pages

  • Re: Service accounts best practices
    ... > The only people who should have domain admin rights are the exact people ... > domain admin work and it should be a very small group. ... >>>Joe Richards Microsoft MVP Windows Server Directory Services ... >>>>Can someone point me to a guide to securing service accounts? ...
    (microsoft.public.win2000.security)
  • Re: Permissions to unlock Administrator account?
    ... Use delegation for everything else. ... The Administrator accounts should have a very long, complex, password, be ... domain admin, and one for general day to day use. ... leaving only the Administrator account there (I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Securing workstations from IT guys
    ... It sounds like you have generic domain admin accounts - I'd change that immediately, and create what are called 99 accounts. ... Change all Local Admin passwords so that even IT helpdesk/other doesn't know them. ... Is there an auditing on PC that can be enabled to track/log incoming connections to C$ and pop up and alert whenever someone tries it out from a remote machine. ...
    (Security-Basics)
  • Re: Changing the domain password policy
    ... You could try to look into your AD event logs and check for Successful logons for the domain admin account. ... While the biggest thing to do is make sure you know your environment and what service accounts are used where, eventually you'll find yourself stuck and you just need to make the change and deal with what breaks. ... Time has come to change the domain admin password. ...
    (Security-Basics)
  • Re: NT4 to Windows 2003 AD Migration Question
    ... You want something that can map the accounts from the source to the ... > I have around 1500 workstations, a couple hundred servers. ... > seems most tools want domain admin on the AD side as well. ... We are tasked with building the OU from scratch, so SID history ...
    (microsoft.public.windows.server.active_directory)