Only Members of the Administrators Group Can Retrieve the ntSecurityDescriptor Attribute from an IDirectorySearch Result Set

Users who are not members of the Administrators group cannot retrieve the ntSecurityDescriptor attribute in a result set from an IDirectorySearch search operation, yet members of the Administrators group can retrieve it.

To work around this problem, you can have the code bind to each object individually by using the IADs interface or the IDirectoryObject interface and then retrieve the ntSecurityDescriptor attribute for each object. This workaround is much less efficient than returning the ntSecurityDescriptor attribute from a search. It takes several times longer to complete.
Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article. This problem was first corrected in Microsoft Windows 2000 Service Pack 4.

