Archived from groups: microsoft.public.win2000.active_directory (More info?)
Hi all,
I have a problem regarding denying account operators deleting users in a
windows 2003 active directory domain. I thought it would be quite straight
forward but it actually wasn't. I added and ACE to one OU by setting
'Delete', 'Delete Sub-tree' and 'Delete All Child Objects' (which will set
all other granular delete flags) set to deny for members of account
operators group and apply it on this object and all child objects. I assumed
that, these setting (deny ACEs) will be reduced from rights any member of
account operators group will be granted by group membership but account
operators can still delete users! As I investigate more I find out that
effective permission on the OU is correct, account operators can not delete
anything. But effective permission on users objects directly beneath that OU
shows that account operators have full permission and deny ACE was
overridden somehow. by the way audit log showed that the account operator
has deleted the user successfully.
does any one know what is it all about??
Thanks in advance
Hi all,
I have a problem regarding denying account operators deleting users in a
windows 2003 active directory domain. I thought it would be quite straight
forward but it actually wasn't. I added and ACE to one OU by setting
'Delete', 'Delete Sub-tree' and 'Delete All Child Objects' (which will set
all other granular delete flags) set to deny for members of account
operators group and apply it on this object and all child objects. I assumed
that, these setting (deny ACEs) will be reduced from rights any member of
account operators group will be granted by group membership but account
operators can still delete users! As I investigate more I find out that
effective permission on the OU is correct, account operators can not delete
anything. But effective permission on users objects directly beneath that OU
shows that account operators have full permission and deny ACE was
overridden somehow. by the way audit log showed that the account operator
has deleted the user successfully.
does any one know what is it all about??
Thanks in advance