Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I've created a new OU under the root of the domain, in which to store some contacts I only want certain users to be able to access.

 

I changed the NTFS permissions of the OU to stop inheriting permissions from the parent. Then removed entries such as Authenticated Users - Read. However, when I create a new contact in the OU, it still gets an ACE for Authenticated Users - Read.

 

I assume this entry is coming from some default ACL, but I don't know where?

 

thanks

Posted
The domain controller. It's preventing you from breaking Active directory.

 

I can manually remove the ACEs that are allocated to the objects by default, so why can I not specify this at the OU level?

 

You could try adding the deny permission for the other security group

 

That's probably do-able, but I'd rather just allocate access to users who need it, rather than allocate to everyone then try to stop access.

 

thanks

Posted
I can manually remove the ACEs that are allocated to the objects by default, so why can I not specify this at the OU level?

 

While it (barely) makes sense to prevent AD objects from being replicated by removing read permissions from them. Preventing replication of an entire OU will cause the ntfrs service to generate replication errors.

Posted
I can manually remove the ACEs that are allocated to the objects by default, so why can I not specify this at the OU level?

 

While it (barely) makes sense to prevent AD objects from being replicated by removing read permissions from them. Preventing replication of an entire OU will cause the ntfrs service to generate replication errors.

 

My understanding was that FRS operated in the system context, is that not the case? I've found that objects without Authenticated Users-Read still replicate fine.

Posted

My test contact has the following permissions set:

Administrators: All but full control

Domain and Enterprise Admins: Full Control

Exchange Enterprise Servers: Special

System: Full Control

 

This object was replicated across the 3 DCs fine. Should that not be working then?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...