Select the product you need help with
The "Effective Permissions" tab may report incorrect permissions in Windows Server 2003Article ID: 933071 - View products that this article applies to. On This PageProblem descriptionWhen you use
the Effective Permissions tab to determine the
permissions
that a
user has for
a certain resource in the domain on a Windows Server 2003-based computer, the
results
that are displayed in the user interface
are inconsistent
with the actual permissions of the user for
that resource. Specifically, check
boxes for some Allow
permissions may appear
unchecked.
Or, check boxes for some Deny
permissions may appear
checked. This problem occurs when one of the following conditions is true:
If you are running the Active Directory administrative tools on a member of one domain and you connect the administrative tools to a domain controller in another domain, you may also see incorrect effective permissions results. Note Because different effective permissions results are displayed when objects are accessed through a global catalog server that is running in another domain, Microsoft discourages securing objects in Active Directory by using domain local groups. CauseThe properties dialog box uses the Authorization Manager
Runtime (AuthZ.dll) engine.
This engine uses a Kerberos Service for User (Kerberos S4U)
transaction to obtain a token of the user. However, this token is not relative to the resource server. Instead, this token is relative to
the administrative station or to the
user who executes the management tool. Therefore, one of the following
scenarios occurs:
ResolutionTo avoid this problem, make sure that you take the following actions when you check
a user's
effective permissions for a resource:
To use the hotfixYou should apply this hotfix to the computer on which you want to run the administrative tools.To have us set the UseGroupRecursion registry entry for you, go to the "Fix it for me" section. If you would rather set the UseGroupRecursion registry entry yourself, go to the "Let me fix it myself" section. Fix it for meTo set the UseGroupRecursion registry entry automatically, click the Fix this problem link. Then, click Run in the File Download dialog box and follow the steps in the wizard.Note this wizard may be in English only; however, the automatic fix also works for other language versions of Windows. Note If you are not on the computer that has the problem, you can save the automatic fix to a flash drive or to a CD, and then you can run it on the computer that has the problem. Now go to the "Did this fix the problem?" section. Let me fix it myselfImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756 To use the UseGroupRecursion registry entry, follow these steps:
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows
Now go to the "Did this fix the problem?" section. Did this fix the problem?After you use the registry entry to change the group recursion method, you must take the following actions:
Check whether the problem is fixed. If the problem is fixed, you are finished with this article. If the problem is not fixed, you can contact support
(http://support.microsoft.com/contactus)
.Hotfix informationA supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix. Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site: http://support.microsoft.com/contactus/?ws=support Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.
(http://support.microsoft.com/contactus/?ws=support)
PrerequisitesYou must have Windows Server 2003 Service Pack 1 or Windows Server 2003 Service Pack 2 installed to apply this hotfix. For more information about Windows Server 2003 service packs, click the following article number to view the article in the Microsoft Knowledge Base:889100
(http://support.microsoft.com/kb/889100/
)
How to obtain the latest service pack for Windows Server 2003
Restart requirementYou must restart the computer after you apply this hotfix.Hotfix replacement informationThis hotfix does not replace any other hotfixes.File informationThe English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.Windows Server 2003 with Service Pack 1, x86-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, x86-based versionsCollapse this table
Windows Server 2003 with Service Pack 1, Itanium-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, Itanium-based versionsCollapse this table
Windows Server 2003 with Service Pack 1, x64-based versionsCollapse this table
Windows Server 2003 with Service Pack 2, x64-based versionsCollapse this table
StatusMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section. More informationFor more information about
software update terminology, click the following article number to view the
article in the Microsoft Knowledge Base: 824684 For
another specific symptom of this problem, click the following article number to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/824684/LN/
)
Description of the standard terminology that is used to describe Microsoft software updates884049
(http://support.microsoft.com/kb/884049/
)
Access control lists may report incorrect information in Windows Server 2003
PropertiesArticle ID: 933071 - Last Review: October 8, 2011 - Revision: 4.0 APPLIES TO
|



Back to the top








