I too have seen this issue crop up due to a user object belonging to an
administrative group. There is a Microsoft KB article about it which may
help shed some light if this is the case for you.
http://support.microsoft.com/default.aspx?scid=kb;en-us;817433


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Rachui, Scott
Sent: Wednesday, January 12, 2005 11:01 AM
To: [email protected]
Subject: RE: [ActiveDir] Reset security on user object

If that user was ever part of an administrative group, AdminSDHolder would
have disabled inheritance on that object to ensure that it only received the
security settings it was providing.  If you remove that user from an
administrative group, we've seen that the inheritance checkbox is not
automatically re-enabled.

I'd check that first, just to make sure the user object is inheriting
policies from the OU.  That's been our issue every time this has come up.

Scott

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Jason Benway
Sent: Wednesday, January 12, 2005 9:43 AM
To: '[email protected]'
Subject: [ActiveDir] Reset security on user object


'somehow' inheritance on some user objects has been removed. How can I set
all user objects to enable inheritance.

Also how can I setup auditing for when attributes of a user object change?

Thanks,jb
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to