Delegate permission to manage „User cannot change password“ in User ‚Account Options‘

Hey, have you noticed, when you delegate write permissions for nt_SecurityDescriptor, you still cannot change an option ‚User cannot change password‘ ? When you try mark this option and save, all looks fine, because you can save it, but once you open user account properties again, you see that option ‚User cannot change password‘ is blank :\ . This is cause by missing permission to add ‚Everyone‘ – DENY in security Tab. Yes, you also must have permission to modify permission of user object. If you do not want to give Full permission, you must explicitly add and allow ‚modify permissions‘

User Object – Account Options

marwin se představuje:

IT Engineer Design, Implementation and Administration of Microsoft products. Active Directory and MS Exchange systems, Hyper-V, SCOM
Příspěvek byl publikován v rubrice Active Directory. Můžete si uložit jeho odkaz mezi své oblíbené záložky.