All,
I am attempting to delegate full control of one OU to a particular
group of Admins. I have run the Delegation Wizard, selected the group,
customized a task to delegate permissions to the folder, all existing
objects in the folder and the creation of new objects and then selected
Full control. I checked the security tab of the OU and the group is there
with full control. I checked some of the sub OU's and this group is given
full control over them via inheritance.
I am running into trouble with some specific objects. These security
settings did not filter down to some groups and users. I attempt to
manually give the group full control and it allows me to add them. I check
it again a few minutes later and the group is gone. Does anybody know what
would cause this? As far as I know there are no scripts or GPO's affecting
this OU that would cause this to happen.
List info : http://www.activedir.org/List.aspx
List FAQ : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/