Welcome to Sign in | Join | Help
in
Home Blog Forums

Permissions not inheriting to child objects in AD

Last post 03-20-2008, 9:43 AM by AndyJG247. 4 replies.

Sort Posts: Previous Next
  •  03-19-2008, 12:50 PM 1774

    Permissions not inheriting to child objects in AD

    Strange thing happening on a WIndows 2003 AD, i have an OU and in this OU i have user objects imported from another domain. The problem is only Domain Admin accounts have access to the objects in the OU despite me assigning full control access to other groups. Effective permissions for these groups look ok but when i select a child object the permissions have not filtered down from the parent OU, despite inherit permissions from parent option being ticked on the object.

    Any ideas? Driving me nuts!!



    The only thing to do with good advice is pass it on. It is never any use to oneself.


  •  03-19-2008, 2:54 PM 1775 in reply to 1774

    Re: Permissions not inheriting to child objects in AD

    When you applied the permissions did you set it for this object "and all child objects" (had to ask,sorry).  Is the "apply to objects only in this container within advanced ticked for your permissions?

    Maybe, if only Domain Admins have permissions then AD doesn't have the ability to change them.  Can you add SYSTEM with full control?

    Maybe use adsiedit.msc as well to check and/or add permissions? 


    Also try clicking the "default" button for permissions?


    Finally who is down in the "owner" tab?


    cheers
    Andy
  •  03-20-2008, 6:32 AM 1776 in reply to 1775

    Re: Permissions not inheriting to child objects in AD

    Permissions are set for this object and all child objects, the inherit from the parent permission entries that apply to child objects.Include these with entries explicitly defined here option is ticked. SYSTEM has full control. The Owner is Domain Admins. Tried DEFAULT button with no joy.

    Can see the objects but just can't modify them. Very bizarre. Not sure how to use Adsiedit so might read up on that. Also swithered if the Delegate Control wizard might work?

     



    The only thing to do with good advice is pass it on. It is never any use to oneself.


  •  03-20-2008, 6:46 AM 1777 in reply to 1776

    Re: Permissions not inheriting to child objects in AD

    DOH!!! I am soooo embarrassed and ashamed to say that i have discovered why it wasn't working.........the drop down box for the permissions was not set to this object and child objects!, it was only set to this object only. I thought it was, on the word of another admin who set it up. I should have checked this and it's the first thing you suggested Andy.

    Gonna put it down to a particularly bad day and i must apologise for wasting your time Andy.

     



    The only thing to do with good advice is pass it on. It is never any use to oneself.


  •  03-20-2008, 9:43 AM 1778 in reply to 1777

    Re: Permissions not inheriting to child objects in AD

    No worries, glad it was sorted.
    I wouldn't worry about the embarrasment, I've done it many times.

    cheers
    Andy
View as RSS news feed in XML


All postings are provided "AS IS" with no warranties, and confer no rights.
Microsoft product screen shot(s) reprinted with permission from Microsoft Corporation.