Article ID: 927068 - Last Review: October 11, 2007 - Revision: 1.2 When you use the Dsrevoke command-line tool to report permissions for all the organizational units in a Windows Server 2003-based domain, the tool may not return all the access control entries
SYMPTOMSOn a Microsoft Windows Server 2003-based domain controller, you run one of the following command lines to report the permissions for all the organizational units in a domain:
Notes
No ACEs for domain\principalname CAUSEThis issue occurs because the report range of the Dsrevoke tool is limited by the MaxPageSize setting. RESOLUTIONTo resolve this issue, run the following command to individually search organizational unit trees so that the total number of organizational units is less than the value of the MaxPageSize setting: dsrevoke /report /root:ou=OU_Name STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATIONThe Dsrevoke tool cannot report permissions when you use the (/) character in the name of an organizational unit. If there is an organizational unit whose name contains the (/) character, the Dsrevoke tool will return the following error message: Error occurred in finding ACEs REFERENCES
For more information about the MaxPageSize setting, click the following article number to view the article in the Microsoft Knowledge Base:
315071
(http://support.microsoft.com/kb/315071/
)
How to view and set LDAP policy in Active Directory by using Ntdsutil.exe
APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
