I don't care which ones, specifically I need to find which accounts have "Include inheritable permissions from this object's parent" *unchecked* when looking at "advanced" area of the security tab of an object in ADUC. The few I have found the hard way seem to have no rhyme or reason why they are set that way.
I think I can make something workable from your script, thanks! Dave Lum - Systems Engineer [EMAIL PROTECTED] - (971)-222-1025 "When you step on the brakes your life is in your foot's hands" From: Michael B. Smith [mailto:[EMAIL PROTECTED] Sent: Monday, February 25, 2008 3:04 PM To: NT System Admin Issues Subject: RE: AD user property export Inherit WHICH permissions? If you can already script, you can get what you need from a sample ACL script I wrote. And I wouldn't be surprised if iCACLS couldn't do this. Or subinacl. http://theessentialexchange.com/blogs/michael/archive/2007/11/13/display ing-security-on-active-directory-exchange-and-registry-objects.aspx Regards, Michael B. Smith MCSE/Exchange MVP http://TheEssentialExchange.com From: David Lum [mailto:[EMAIL PROTECTED] Sent: Monday, February 25, 2008 5:30 PM To: NT System Admin Issues Subject: RE: AD user property export Bump once...anyone? From: David Lum [mailto:[EMAIL PROTECTED] Sent: Friday, February 22, 2008 11:25 AM To: NT System Admin Issues Subject: AD user property export I need to find all my AD user accounts that do not inherit their permissions from their parent OU - anyone have a script for that, or send me what attribute I need to specify? Dave Lum - Systems Engineer [EMAIL PROTECTED] - (971)-222-1025 "When you step on the brakes your life is in your foot's hands" ~ Upgrade to Next Generation Antispam/Antivirus with Ninja! ~ ~ <http://www.sunbelt-software.com/SunbeltMessagingNinja.cfm> ~
