Default User object security

Windows 2003 SP2

I am trying to fix a problem where delegation of control is not working 
properly to usr OUs.  I ca't seem to keep permissions on user account objects 
that allow user accounts to be moved between OUs.  I think it may be related 
to protected account membership on the user objects themselves.  ALso the 
"inherit permissions from parent" is unchecked on user objects.  Certain user 
new user objects work fine and are inheriting.  What are the default security 
to use on user objects so that i can remvoe membership from protected groups 
and how should I allow inherit permissions from OU container so i can delgate 
permisions.?
0
Utf
11/24/2009 8:35:02 PM
windows.server.active_director 902 articles. 0 followers. Follow

2 Replies
632 Views

Similar Articles

[PageSpeed] 40

Hello 2010,

Please describe in detail what you have configured in delegate control, so 
we can reproduce your problem.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers 
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm 


> Windows 2003 SP2
> 
> I am trying to fix a problem where delegation of control is not
> working properly to usr OUs.  I ca't seem to keep permissions on user
> account objects that allow user accounts to be moved between OUs.  I
> think it may be related to protected account membership on the user
> objects themselves.  ALso the "inherit permissions from parent" is
> unchecked on user objects.  Certain user new user objects work fine
> and are inheriting.  What are the default security to use on user
> objects so that i can remvoe membership from protected groups and how
> should I allow inherit permissions from OU container so i can delgate
> permisions.?
> 


0
Meinolf
11/24/2009 9:45:39 PM
Sounds like you understand that protected groups are causing the inherit 
flag to be unchecked.
http://technet.microsoft.com/en-us/magazine/2009.09.sdadminholder.aspx

What you haven't defined is what you want the users who are in protected 
groups to be able to do once they have been removed from these groups.  It 
really is not possible to tell you what the specific permissions a protected 
group has.  Just define what you need users to be able to do and I believe 
the folks monitoing this NewsGroup will be able to guide you through it.

-- 
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"2010" <2010@discussions.microsoft.com> wrote in message 
news:80E4E1BB-AED5-468A-8931-B7DF07252FBA@microsoft.com...
> Windows 2003 SP2
>
> I am trying to fix a problem where delegation of control is not working
> properly to usr OUs.  I ca't seem to keep permissions on user account 
> objects
> that allow user accounts to be moved between OUs.  I think it may be 
> related
> to protected account membership on the user objects themselves.  ALso the
> "inherit permissions from parent" is unchecked on user objects.  Certain 
> user
> new user objects work fine and are inheriting.  What are the default 
> security
> to use on user objects so that i can remvoe membership from protected 
> groups
> and how should I allow inherit permissions from OU container so i can 
> delgate
> permisions.? 


0
Paul
11/25/2009 1:19:55 PM
Reply:

Similar Artilces:

How do I undo a default setting
Outlook was not downloading my emails, so I went to "help" and selected "detect and repair". I selected "Discard my customized settings and restore default settings" and didn't know it was going to wipe my whole Outlook clean.....is there any way to go back and undo the default? What are you missing and what do you want to restore? -- Robert Sparnaaij [MVP-Outlook] www.howto-outlook.com Tips of the month: -Creating Signatures -Create an Office XP CD slipstreamed with Service Pack 3 ----- "tanya" <mnlync@frontiernet.net> wrote in mess...

How can I secure Outlook when using RPC over HTTP?
Hello! I have my laptop running XP Pro SP2 and Outlook 2003 set up to access my Exchange account via RPC over HTTPS. I have a strong password required to get into the laptop, but I know if it gets stolen, someone can probably hack the password with a Linux disk. Is there any way to password-protect my Exchange profile on the laptop so that a password must be entered to see the contents of the Exchange account? Thanks for the help! Gregg Hill There is no foolproof way to avoid a cunning cracker from accessing your notebook/contents. The best way to avoid this is to not use a compu...

Setting a default open folder
Hi- I'm using Outlook 2002 using Imap. The folder list always starts at Outlook Today, I want to have my imap inbox be the default open folder when I start Outlook. At the very least have the imap account expanded. I'm transferring a bunch of people from Netscaoe mail to Outlook and want to make the transition an easy one. Thank you ...

MFC and User Defined objects
Greetings, I am trying to PostMessage from a user defined generic class/object in MFC Dialog based application to Dialog/main window. I don't know how to do that. I am utilizing worker threads. A thread instantiates an object(from user defined generic class) and utilizes newly created object. What user defined object code does is actually launch a process, for sake for argument lets say, Windows Notepad.exe using CreateProcess. As long as that process is running, I want to PostMessage that updates a progress bar on Main GUI dialog. I can do it if I embed the code right into my appli...

AD Security Groups break Authentication
Hello, I seem to be having a strange problem with my Active Directory user accounts. We have a Windows 2008 AD domain, with our only domain controller located at a remote data center. All of our locations have connectivity to the data center through a private MPLS network, with varying speeds. Users at my largest office seem to lose the ability to properly authenticate to AD if they are added to too many security groups. At first we thought it was a specific group causing the problem, but any new group will reproduce the issue. There doesn't seem to be any magic n...

Run-time error '429' ActiveX component can't create object
Hi I have an application running in Access 2003 that is trying to open a second Access application and get the following error Run-time error '429' ActiveX component can't create object The references all seem OK - I have references to Visual Basic for Applications MS Access 10.0 Object Library MS DAO 3.6 Object Library MS ACtiveX Data Objects 2.1 Library OLE Automation My code is as follows Dim acApp As Access.Application Dim strDBPath As String strDBPath = "C:\NewAppName.mdb" Set acApp = New Access.Application With acApp ..OpenCurrentDatabase strDBPath ..DoCmd.O...

Smartlist Builder
I have played around with several security settings but my user still cannot see the new reports I built in Smartlist Builder. I understood the user does not have to have it installed to see it in the regular Smartlist. The tasks I have assigned are as follows: Category: Other Product: Smartlist Type: Smartlist Object Series: Smartlist Objects I checked off my new reports. Also added: Category: Other Product: Smartlist Builder Type: Smartlist Builder Permissions Series: Smartlist Builder I checked off "View Smartlists with SQL Tables SmartList Bui...

Change default filename
Hi, Is there any way to change the default filename in excel 2003? ie. a blank file is opened and called: "Book X.xls" Whereas, I want all files to be called: Finance_Planning_X.xls" This way, I can save time by automatically having my file naming convention built into Excel, and I won't have to remember it going forward. Thanks! Chris About the best you can do would be to create a Template(*.XLT) and use that as your default workbook. Open new workbook. Do any customizing you may need. File>Save As>File Type>Template(*.xlt) Name it Finance_Planning Clo...

Passing a CEdit object to another class..
This is how I've created a thread.. void CvcatTransmit::OnTransmitStart() { thread = (CThread *)AfxBeginThread(RUNTIME_CLASS(CThread), THREAD_PRIORITY_NORMAL, 0, //stacksize CREATE_SUSPENDED); thread->SetMe = true; thread->ResumeThread(); } CThread is a class that inherits CWinThread. Now, in my thread I need to be able to update my edit boxes which reside in the CvcatTransmit class. this is what I've tried: inside of Thread.h CEdit ...

link sent to user does not work
An e-mail with a link to a file on our file server does not work. The sender (a domain admin) pasted the address into the e-mail (ex. <\\server\share\file>) but the recipient was not able to click on it. The recipient is a domain admin with full rights to the folder where the file is stored. I had the sender resend the email to me and I was able to click on the link and open the file. Any help would be appreciated. Let me preface that I have just joined this group, and am not near as knowledgable about this stuff as others, but like taking stabs. Is the recipient opening his...

Unable to create new user mailbox. event id 9562
Trying to setup a new users and I can create the account just fine but no mailbox is created. When I look in the event log I see ID-9562 and that talks about the RUS. All teh info points to a rebuild or RUS which i did and still no luck with the mailbox. I tried to delete the users and re-create him with the same luck. I also tried to create a different user and still can't create a mailbox. All the KB articles point to a rebuild and that doesn't get it done. Anyone have any thoughts on this. This is pretty frustrating. Any help or KB articles would be greatly appreciate...

Security Permissions 06-02-07
I am using CRM 3.0. In that I have 2 Business Units. Users are given permissions for viewing/editing Oppurtunities on USER LEVEL and viewing/editing Customers on ORGANIZATIONAL LEVEL. When one user from First BU creates oppurtunity using Customer created by user of Second BU, then this Oppurtunity is also viewable/editable to the user of Second Business Unit, whereas owner of that particular opprtunity is the user from first BU. How can I prevent user from Second BU viewing/editing that Oppurtunity? Please help! Kamal are both BU in the same level or child? "Kamal Bohra" <...

Copying The Windows User Account
Am I able make a copy of the complete Windows user account; so that when I do a clean install I can restore the account to its previous state? Is creating the exact user name and account type sufficient, or is there other information needed? How do I do this, I am running XP Home Edition on a 32 bit machine. On Sat, 28 Aug 2010 11:24:03 -0700, paul <paul@discussions.microsoft.com> wrote: >Am I able make a copy of the complete Windows user account; so that when I do >a clean install I can restore the account to its previous state? Is creating >the exact user nam...

Look at these security update
--wpxhtpbmrmsmmz Content-Type: multipart/related; boundary="gpfmogvvgagrxl"; type="multipart/alternative" --gpfmogvvgagrxl Content-Type: multipart/alternative; boundary="uxubtxafyzmt" --uxubtxafyzmt Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Microsoft Customer this is the latest version of security update, the "October 2003, Cumulative Patch" update which eliminates all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express as well as three newly discovered vulnerabilities. Install ...

How to calculate the present value of a security, $5000 @ 7%, 20y.
I'm trying to use excell to calculate the present value of a security that will pay $5000.00 in 20 years at 7% interest. PV=FVn/(1+I)N There is a PV function in Excel. Have a look in the Excel built-in Help for more info on how to use the function. Regards, Tom "catslgc" wrote: > I'm trying to use excell to calculate the present value of a security that > will pay $5000.00 in 20 years at 7% interest. PV=FVn/(1+I)N ...

What type of tech user are you?
We pose this question in our blog with a goal of better defining how many people fall into our notquitegeek category. There are 10 categories, look to th blog for more info and please post your comments. www.notquitegeeks.blogspot.com and some freebies at www.notquitegeeks.com enjoy ...

Default font color
How do I change the default color for a sheet such that if I retype a cell that is currently black, and I want to make it blue, I don't have to keep going back to the Font Color button? Thanks! Jason Conditional formatting will allow you to automatically change colours based on three conditions. Choose, Format, Conditional formatting, and enter a first condition e.g. Cell value > 50 then change the colour background. More than three conditions will require a macro. Regards Peter >-----Original Message----- >How do I change the default color for a sheet such that if ...

User Entity in isv.config?
Anybody know if it is possible to create a User entity tag in isv.config so that I can add a tab to the User's detail screen? It's unsupported and undocumented... but yes you can. Under the "Entities" node, simply add a "<systemuser>" tag and follow the format used by the other entities. This should work for all entities that are built on the Customizable Form Framework (basically most but Activities). Aaron Elder Director, Software Development Invoke Systems Solid technology. Sound thinking. http://www.invokesystems.com "AW" <AW@discus...

User Defined Fields--Employee Maintenance Screen PR & HR
In looking through the table/field descriptions I do not find the additional user defined field names associated with the PR/HR modules. When I tried to run a smartlist and attach the fields they do not appear in the window as available fields/columns. I have modified the labels and need to run reports on those specific user defined fields. Has anyone created such a report? If not, where can I locate the field names? I am a new user to this system and any assistance someone could provide would be helpful. Hi, Since there are several places with user defined fields availab...

Set default SMTP server settings
Hello, I'm running 1 Exchange Server 2003 SP1 on W2k SP4. I'm trying to increase my mail size limit. However in the ESM settings, the SMTP Virtual server doesn't adjust to the new settings. ie. I can set it to 10240 but mail is still blocked that is smaller. The server is still recognizing my old setting - 4096kb. I can change it and put whatever number I want in heir but Exchange isn't recognizing the new number. I know it's still recognizing the old setting since when I telnet into exchange and do a ehlo command I see the size set to 4096. I've been experienci...

Windows Security Center/Antivirus Problem
For the past couple of days Windows Security Center has been sending pop-up alerts on my husband's computer saying that his Virus Protection is out of date. It is NOT out of date. The antivirus program (Ca antivirus) shows the last product update as today. A virus scan comes up clean. So does a spyware scan (Ad-Aware and Malwarebytes). Any ideas? sharonf wrote: > For the past couple of days Windows Security Center has been sending > pop-up alerts on my husband's computer saying that his Virus Protection > is out of date. It is NOT out of date. The antivirus pr...

How to create a new default template? HELP!
Hi I need to expertise on this: how can we customize the default template in Excel 2002 (e.g., Book1.xls) I already insert a file in my C:\Documents and Settings\steve\Application Data\Microsoft\Excel\XLSTART and it works perfect But when I add with File / New file, it gives us the Book1.xls. How can I go to update the Book file with our customizations Anyone can help me Many thanks for your help on this .. Steve Hi Steve Name it Book.xlt And for a Sheet: Sheet.xlt Every new file/sheet you create is based on this files -- Regards Ron de Bruin (Win XP Pro SP-1 XL2000-2003) www.rondebruin....

Default Dates
I have a worksheet in Excel 2003 that has 2 columns with dates paste linked from another workbook. One is a start date and the other a finish date. I want excel to automatically default any start date to 1/04/05 where that date is before 1/04/05, and in the finish date column, to automatically default the date to 31/03/06 for any dates that are after 31/03/06 or there is no date at all for that column. I don't want the default dates to alter any dates that fall from 1/04/05 to 31/03/06 because they will be relevant dates I need to keep. Can this be done? You can use something s...

A folder Deleted or Disappeared from User Inbox
Hi all, One of my User has issue about one of the folder being accidently deleted or disaapeared from his Mailbox while doing ActiveSync on his PDA. Is there a way I can reterive that folder. Things I cannot do. Do a restore on his mailbox as the backups ran 20 days ago..:( I dont have mailbox Recovery configured yet. Any good way or ideas to retreive that folder. A- On 28 Feb 2007 14:36:08 -0800, "Barundi" <pannuz@gmail.com> wrote: >Hi all, > >One of my User has issue about one of the folder being accidently >deleted or disaapeared from his Mailbox while ...

receive email messages sent to a new user account
i have set up a new user account for email and now when I send a message to them I receive a copy of the same message in my inbox. i have reviewed the account settings and all appears normal. am I missing something? what should I do as I should not be receiving messages addressed to somebody else. ...