Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links



adminCount not resetting after user removed from protected group

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 14-08-2009
TPGBrennan
 
Posts: n/a
adminCount not resetting after user removed from protected group

Ran into the typical adminSDHolder issue of permissions being reset after an
hour. The puzzle was that it was affecting some users not in any protected
groups. I ran ADFind from joeware and it returned all the users with the
adminCount set to 1; this included some disabled users who are members of
nothing other than Domain Users. i confirmed the adminCount value in
ADSIEdit. i thought the adminCount was supposed to automatically reset afte
a user is removed from a protected group? I assume it's safe to use ADSIEdit
to reset the value to Not Set on users no longer in the protected groups?
Reply With Quote
  #2  
Old 14-08-2009
Cary Shultz
 
Posts: n/a
Re: adminCount not resetting after user removed from protected group

It will never change on its own. I have encountered this in every
environment that we manage. In a couple of environments there were users
who *were* in a protected group two years ago and the value for adminCount
is still "1".

I have always used ldifde to do what you are asking....but you can use
adsiedit as well.

HTH,

Cary

"TPGBrennan" <TPGBrennan@discussions.microsoft.com> wrote in message
news:24599D89-2134-4C3E-9396-F018EE18A21B@microsoft.com...
> Ran into the typical adminSDHolder issue of permissions being reset after
> an
> hour. The puzzle was that it was affecting some users not in any
> protected
> groups. I ran ADFind from joeware and it returned all the users with the
> adminCount set to 1; this included some disabled users who are members of
> nothing other than Domain Users. i confirmed the adminCount value in
> ADSIEdit. i thought the adminCount was supposed to automatically reset
> afte
> a user is removed from a protected group? I assume it's safe to use
> ADSIEdit
> to reset the value to Not Set on users no longer in the protected groups?


Reply With Quote
  #3  
Old 15-08-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: adminCount not resetting after user removed from protected group

Hello TPGBrennan,

It is correct, after adding a user account to a protected group and removing
it the admincount will stay on 1 until you reconfigure it. After removing
the account from the group, enable ACL inheritance, reset the default permissions
and set "adminCount=<not set>"

See:
http://blogs.dirteam.com/blogs/jorge...05/16/981.aspx

http://blogs.dirteam.com/blogs/jorge.../11/16/86.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Ran into the typical adminSDHolder issue of permissions being reset
> after an hour. The puzzle was that it was affecting some users not in
> any protected groups. I ran ADFind from joeware and it returned all
> the users with the adminCount set to 1; this included some disabled
> users who are members of nothing other than Domain Users. i confirmed
> the adminCount value in ADSIEdit. i thought the adminCount was
> supposed to automatically reset afte a user is removed from a
> protected group? I assume it's safe to use ADSIEdit to reset the
> value to Not Set on users no longer in the protected groups?
>



Reply With Quote
  #4  
Old 26-08-2009
JPolicelli [MVP-DS]
 
Posts: n/a
Re: adminCount not resetting after user removed from protected group

You may find the following useful:
http://technet.microsoft.com/en-us/m...minholder.aspx


--

JPolicelli, MVP - Directory Services

http://www.policelli.com
http://policelli.com/blog

This posting is provided AS IS with no warranties and confers no rights.
Always plan and test.

----

"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb662d5418cbeb5537007c46@msnews.microsoft.com...
> Hello TPGBrennan,
>
> It is correct, after adding a user account to a protected group and
> removing it the admincount will stay on 1 until you reconfigure it. After
> removing the account from the group, enable ACL inheritance, reset the
> default permissions and set "adminCount=<not set>"
>
> See:
> http://blogs.dirteam.com/blogs/jorge...05/16/981.aspx
>
> http://blogs.dirteam.com/blogs/jorge.../11/16/86.aspx
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Ran into the typical adminSDHolder issue of permissions being reset
>> after an hour. The puzzle was that it was affecting some users not in
>> any protected groups. I ran ADFind from joeware and it returned all
>> the users with the adminCount set to 1; this included some disabled
>> users who are members of nothing other than Domain Users. i confirmed
>> the adminCount value in ADSIEdit. i thought the adminCount was
>> supposed to automatically reset afte a user is removed from a
>> protected group? I assume it's safe to use ADSIEdit to reset the
>> value to Not Set on users no longer in the protected groups?
>>

>
>

Reply With Quote
  #5  
Old 26-08-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: adminCount not resetting after user removed from protected group

Hello JPolicelli [MVP-DS],

Really good article about the relationship and "why is this". Also the steps
to modify easy described. Well done :-)

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> You may find the following useful:
> http://technet.microsoft.com/en-us/m...minholder.aspx
> http://www.policelli.com
> http://policelli.com/blog
> This posting is provided AS IS with no warranties and confers no
> rights. Always plan and test.
>
> ----
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
> news:ff16fb662d5418cbeb5537007c46@msnews.microsoft.com...
>
>> Hello TPGBrennan,
>>
>> It is correct, after adding a user account to a protected group and
>> removing it the admincount will stay on 1 until you reconfigure it.
>> After removing the account from the group, enable ACL inheritance,
>> reset the default permissions and set "adminCount=<not set>"
>>
>> See:
>> http://blogs.dirteam.com/blogs/jorge...05/16/981.aspx
>> http://blogs.dirteam.com/blogs/jorge.../11/16/86.aspx
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Ran into the typical adminSDHolder issue of permissions being reset
>>> after an hour. The puzzle was that it was affecting some users not
>>> in any protected groups. I ran ADFind from joeware and it returned
>>> all the users with the adminCount set to 1; this included some
>>> disabled users who are members of nothing other than Domain Users.
>>> i confirmed the adminCount value in ADSIEdit. i thought the
>>> adminCount was supposed to automatically reset afte a user is
>>> removed from a protected group? I assume it's safe to use ADSIEdit
>>> to reset the value to Not Set on users no longer in the protected
>>> groups?
>>>



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "adminCount not resetting after user removed from protected group"
Thread Thread Starter Forum Replies Last Post
Add domain user\group to local admin group problem DangerMaus Active Directory 12 16-10-2009 10:30 PM
Add user in freebsd to secondary group not primary group FreeBSD Operating Systems 3 11-08-2009 07:38 PM
Resetting Group Policy in Windows Server 2003 Icarusul Networking & Security 3 25-04-2009 09:30 PM
Error 1609: User is not a valid user or group !const Operating Systems 3 16-03-2009 03:02 PM
Adding group/user to local Admins group on all workstations? Barkley Bees Window 2000 Help 5 04-07-2008 07:10 AM


All times are GMT +5.5. The time now is 05:03 PM.