Conflicting effective permissions in DC ADUC & workstation/mbrsvr

Conflicting effective permissions in DC ADUC & workstation/mbrsvr

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Conflicting effective permissions in DC ADUC & workstation/mbrsvr IT Guy 09-07-2005
Posted by =?Utf-8?B?SVQgR3V5?= on September 7, 2005, 2:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have a problem that's been nagging us for a few weeks now. A domain user
has been assigned to the print operators group to administer printers for our
domain. Unfortunately, the user can read but not modify printer properties.

I discovered while reviewing effective permissions on individual printer
objects that the user has read only privileges when viewed from either my
local workstation ADUC or a member server ADUC but full control when viewed
from ADUC on any of our DCs. The Print Operators group has full control
under effective permissions when viewed either way.

We are running a Windows 2003 domain with 3 domain controllers. I have run
gpupdate /force but still see the conflicting effective permissions. I am
able to add objects, modify permissions, etc. from both DC and non-DC ADUCs
and have those changes replicate successfully.

Presumably the TRUELY effective permissions are the ones that I am seeing
from non-DC ADUCs because the user is not able to modify printers. Any ideas
why the users effective permissions would be different depending on where I
view them from? Any ideas on why the effective permissions being shown on DC
ADUCs are not working? Thanks!

Similar ThreadsPosted
Scripting Effective Permissions September 19, 2007, 10:52 am
User's Effective Permissions on Domain? May 21, 2007, 6:03 pm
Read Only Access to ADUC July 8, 2005, 9:40 am
Cost Effective Privacy Solutions May 12, 2007, 7:40 am
Conflicting reports on firewall status? February 22, 2006, 7:28 pm
Conflicting IAS remote access policies problem February 14, 2008, 2:19 pm
Possible conflicting info:Help file states that Offline Root CA canot be member server of domain? January 23, 2007, 5:27 pm
Permissions January 4, 2006, 12:34 pm
Permissions July 6, 2006, 9:40 am
Permissions question August 22, 2005, 6:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy