Briefly, AD copies the security descriptor of the
AdminSDHolder object (there is one per domain) to all users, groups, and
computers that are members of administrator groups in that domain. This
makes sure that delegated admins don't change the ACLs on these sensitive
accounts. It also gives the appearance of AD losing or reversing manually made
ACL changes on user objects.
-gil
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Senthil Kumar
Sent: Monday, February 20, 2006 3:40 PM
To: activedir@mail.activedir.org
Subject: [ActiveDir] admin SD holder
Hi,
Can anyone give me the details about admin SD holder.What it is ? What it
do?
K.Senthil