AD User Objects not retaining security



Salutations,

I've run across a strange issue in a Windows 2000 Native AD environment.
There are two Domain Controllers, one is Windows 2000, the other is Server
2003. Server 2003 hosts Exchange 2003.

The issue began when the 2000 DC was hosting all of the FSMO roles. When
new security was added to the security tab of an AD user object, it would
disappear after a period of time, leaving only the SID behind. We don't have
an exact time frame, but it seems to be within an hour.

We went through several layers of troubleshooting, and we've eventually
moved all of the FSMO roles to the 2003 server. Now, the same error seems to
be occuring, but the Security descriptors are completely removed, no SID is
left behind.

I've checked replication with replmon, and ran several dcdiag tests, and
nothing seems out of the ordinary. The only thing I've not explored deeply
is the AdminSDholder object, as described in
http://support.microsoft.com/?id=232199.

I suppose I'm looking for any thoughts as to what else could be causing this
strange issue.
.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #164
    ... Got Storage Security Risks? ... MICROSOFT VULNERABILITY SUMMARY ... Chat Client FTP Server Default Username Credential Weak... ... NetServe Web Server is a compact web server for Microsoft Windows ...
    (Focus-Microsoft)
  • Re: im being held in memory
    ... How can I harden my computer or server to secure it from hackers? ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.security)
  • MS and security: good effort but no cigar
    ... build upon the progress it's already made in security. ... The low-hanging fruit of millions of insecure Windows machines ... Then there's the issue of poorly secured server applications. ... and execute external virus and filtering ...
    (microsoft.public.windowsxp.general)
  • SecurityFocus Microsoft Newsletter #167
    ... MICROSOFT VULNERABILITY SUMMARY ... Multiple Vendor XML Parser SOAP Server Denial Of Service Vul... ... Proactive Windows Security Explorer ...
    (Focus-Microsoft)
  • Re: Group Policy broke my DCs
    ... > need to be very careful with tweaking services on domain controllers. ... > Group Policy - security policy at the OU level which makes it much easier ... > is complied from the Windows 2003 Server Security guide for baseline core ...
    (microsoft.public.windows.group_policy)

Quantcast