Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

AD 2012 - ACL - Allow on This Object Only takes precedence on Deny on This object and all descendant

$
0
0

Hi,

Following my initial bug where I could not block list content by removing the permission from Authenticated Users, I proceeded to implement the work around provided by Microsoft:

* Create a security group

* Deny the list content to members in the security group.

And here I go on my merry way to create the group and Deny the list content permission to the members of that group. As per the description of the popup, the DENY is supposed to take priority over everything. Well.... apparently not.

I used Deny on This object and all descendant, because lets be honest, who wants to go on 200 OUs to remove the list content permission ? (And I am not yet confident enough to do that operation by scripting and not mess it up). But the user in the group were still able to list the content. Apparently the DENY, in my case, only works if I apply it to This object only.

Has anyone else encountered this issue ? And if so, how did you go around to fixing it or making it work?

Thanks


Viewing all articles
Browse latest Browse all 31638


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>