AdminSDHolder Object Affects Delegation of Control for Past Administrator Accounts

Article translations Article translations
Article ID: 306398 - View products that this article applies to.
This article was previously published under Q306398
Expand all | Collapse all

SYMPTOMS

A user or group (for example, helpdesk) is delegated control over an Organizational Unit (OU) by using the Delegation of Control Wizard. One or more users that are located in the OU are made members of the administrators group or a group the user is a member of is made a member of the administrators group. After the user or group is moved out of the administrators group, the helpdesk is unable to manage the user or group of users that were once administrators.

CAUSE

Once a user is added to an administrators group, the "Allow Inheritable Permissions From Parent" security setting is cleared on the user object. When the user is moved out of the administrators group, the "Allow Inheritable Permission from Parent" setting is not automatically added back.

RESOLUTION

If there are users that currently have the delegation-management problem:
  1. Start Active Directory Users and Computers, and then find the appropriate user object.
  2. Right-click the object, click Properties, and then click the Security tab.
  3. Click to select the Allow Inheritable Permission from Parent check box, click Apply, and then click OK.You can now manage the user account.

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

MORE INFORMATION

For additional information about why the inheritance permission is disabled on administrative accounts, click the article number below to view the article in the Microsoft Knowledge Base:
232199 Description and Update of Active Directory AdminSDHolder Object

Properties

Article ID: 306398 - Last Review: March 1, 2007 - Revision: 3.3
APPLIES TO
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server
Keywords: 
kbenv kbprb KB306398

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com