Protecting AD OU's structure against deletion/moves...
- From: Claude Lachapelle <ClaudeLachapelle@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 15 May 2008 14:29:01 -0700
Hi!
I would like to know what is the best practice to protect an AD OU's
structure against unwanted deletion/moves from domain administrators (human
error).
I tried to apply "Deny" to "Delete" and "Delete subtree" to Everyone group
to the root OU I want to protect, but I'm still able to delete sub-OU of
this OU.
Even applying this security settings to a specific OU (ex: test), and
deleting it afterwards is still working!!!
What's wrong? Deny security should not take precedence over normal security???
Thanks.
Claude Lachapelle
Systems Administrators, MCSE
.
- Follow-Ups:
- Re: Protecting AD OU's structure against deletion/moves...
- From: Jorge de Almeida Pinto [MVP - DS]
- Re: Protecting AD OU's structure against deletion/moves...
- From: Dmitri Gavrilov [MSFT]
- Re: Protecting AD OU's structure against deletion/moves...
- From: Paul Bergson [MVP-DS]
- Re: Protecting AD OU's structure against deletion/moves...
- From: Meinolf Weber
- Re: Protecting AD OU's structure against deletion/moves...
- Prev by Date: Re: Temporary users
- Next by Date: Re: Protecting AD OU's structure against deletion/moves...
- Previous by thread: Resource Access between domains
- Next by thread: Re: Protecting AD OU's structure against deletion/moves...
- Index(es):
Relevant Pages
|