Delegated Permissions no longer applied after sometime, please help?

Mart 6 Reputation points
2023-06-09T17:32:46.3466667+00:00

I've been trying to find a solution for sometime now but haven't been able to, I delegated some permissions to user and it does work for time. User is able to login to the server and able to perform the tasks, but after sometime (days), the user will lose its ability to perform the delegated tasks. The options becomes grayed out. I have to remove the user account from the group or user names list under the security tab of the OU and go over the Delegate control wizard to reapply permissions. Any suggestions would high be appreciated.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,080 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,818 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Gary Reynolds 9,391 Reputation points
    2023-06-11T04:47:16.7533333+00:00

    Hi Mart,

    Running the delegation wizard multiple times will not affect the existing permissions that have been assigned, as it only adds more permissions each time it is run.

    The delegation of the Create, Delete, and Manage user accounts, and Reset user passwords and force password change at the next logon will assign the following permissions, permissions have been assigned to the 'Perms' users.

    User's image

    As these permissions will give you full permissions to the user objects, you don't technically need to delegate additional rights to unlock the accounts.

    When you fix the problem, are you removing the users from the groups or just removing the permissions and reapplying them? When you do this, does the user need to restart ADUC to enable the grey options?

    If you want to check that the permissions are still being applied to the user you can either the check the value of the sDRightsEffective attribute and confirm that it's 15 or use https://nettools.net/effective-permissions/ to look at the effective permissions.

    Gary.

    0 comments No comments