users able to write user object memberOf without explicit permissions to do so


i in process of delegating ability support user edit membership of groups. not matters, did adding entry acl of ou gave them (a group they're member of) read\write member descendant group objects in ou. anyway, noticed without doing more delegation support user able add users , groups in ou. how possible without me giving support user other half of needed delegated rights read\write memberof on users?

a few notes:

  1. my support user member of domain users , group mentioned in acl statement.
  2. i understand read on either side of delegation not necessary doesn't hurt (or think).
  3. the users support user able add in varying other ous
  4. based on note 3 seems user can add user in domain group has write member to.
  5. based on note 4, i've looked @ acl on root of domain entries applied descendant user objects , can't find has write member checked. 

this little concerning… help.



you can delegate right add members or remove members groups. in other words delegate right read/write member attribute (forward link) of group.

however, cannot delegate right adjust group memberships of user. in other, cannot delegate right read/write memberof attribute (backlink) of user/computer/group

forward links either multi- or single valued, can managed, can delegated, replicated between dcs

backlinks multivalued, cannot managed, cannot delegated, not replicated between dcs. backlinks managed each individual dc based upon replication of corresponding forward link attribute.

best regards,

jorge


jorge de almeida pinto [mvp-ds] | principal consultant | blog: http://jorgequestforknowledge.wordpress.com/



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file