Problem managing accounts in protected groups



Before I ask my question, here is our basic setup:

We have a single Windows 2003 Domain. Within the domain there are two OUs
that contain users. OU A has users who DO NOT have desktop restictions
through GPOs and OU B is for users who DO HAVE some desktop restrictions. We
have created a new group called Account Management. This group contains users
in both OUs and should have permission to unlock accounts and reset
passwords. The permissions for this group have been applied to OU B and it
all works perfectly. The permissions for this group have also been applied to
OU A.

Here is the problem. Most members of OU A are either members of Domain
Admins or Backup Operators. Even after setting the permissions on the
AdminSDHolder container and having those permissions propagate to the
protected accounts, the Account Mangement group still cannot manage lockouts
or passwords for the users in the protected groups. Users in OU A who are not
in protected groups can be managed properly.
I know that there is a way to remove certain groups from being protected,
but I do not have permission to do that.

How can I get this group to be able to manage members of the protected groups?
I would appreciate suggestions for other things to try, or pointers in the
right direction. Thank you.

--
Technical Support is usually neither.
.



Relevant Pages

  • Re: Problem managing accounts in protected groups
    ... we have two domain admins: ... that someone will give more security permissions to users then to the admins. ... I think you have realized that the account management group is able to reset ... Most members of OU A are either members of Domain ...
    (microsoft.public.windows.server.active_directory)
  • RE: Help: SBS 2003 Exchange Send As permissions not working (and disappearing!)
    ... It seems to be related to the AD AdminSDHolder resetting the permissions ... 318180 AdminSDHolder Thread Affects Transitive Members of Distribution ... Schema Admins ... You have mentioned that one account can work well with "send as". ...
    (microsoft.public.windows.server.sbs)
  • Re: Intermittent Problems Sending Mail As Another User
    ... The mailbox is a normal user account, the account i logon with is ... SEND AS permissions to the mailbox. ... permissions aren't members of any protected group, ...
    (microsoft.public.exchange.admin)
  • Re: Setting permissions in User Security tab is reverting back to previoussetting
    ... The permissions are changing because of the AdminSDHolder object. ... they will always revert back because these are protected groups. ... At the time I had a blackberry and my account was in one of these groups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Inheriting Permissions from Parent
    ... When you delegate permissions using the Delegation of Control wizard, ... Members of protected groups do not inherit permissions ... these permissions are not applied to members ... Within one of my OU's I have many user accounts ...
    (microsoft.public.windows.server.active_directory)