How to delegate permissions on AdminSDHolder users???

InfoTechdude 156 Reputation points
2020-11-04T16:31:24.677+00:00

Hi,

I was wondering how to delegate permissions on AdminSDHolder users??? I found out that some of the accounts are protected by ADMINSHOLDER, but don't really get how to do it. Examples of those accounts would be: Admins, KRBTGT and more:
https://learn.microsoft.com/en-us/windows/security/identity-protection/access-control/active-directory-accounts
Thanks for any clue!

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,595 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,579 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,842 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,986 Reputation points
    2020-11-04T23:22:49.347+00:00

    Hi,

    The SDprop process is the responsible to protect the ACLs of protected account by disabling the inheriting and applying the ACL template of AdminSDHolder on protected objects. This Process run automatically evevry 60 min by minute.

    To know if a account is protected or not by this process , you can check the value of the attribute AdminCount.

    To get more details about this process , I invite you to read this article:

    appendix-c--protected-accounts-and-groups-in-active-directory

    Please don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments

  2. Fan Fan 15,336 Reputation points Microsoft Vendor
    2020-11-05T00:25:28.857+00:00

    Hi,
    Would you please tell what permissions do you want to delegate?
    As Thameur mentioned above :the SDprop process is the responsible to protect the ACLs of protected account by disabling the inheriting and applying the ACL template of AdminSDHolder on protected objects. This Process run automatically evevry 60 min by minute.

    If you want to delegate permission through Delegation of Control wizard, even if you delegate permission to the account, the SDprop process will apply the ACL template of AdminSDHolder on protected objects.

    Or you want to Enabling inheritance on the adminSDHolder container,but one of the two protective access control list (ACL) mechanisms is disabled.(not recommended)
    Or change security on the adminSDHolder container directory.(not recommended)

    Best Regards,


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.