Delegation doesn't work on some Admin accounts

MamadouCoulibali-4946 486 Reputation points
2020-12-20T21:58:52.903+00:00

Hi,

I created a unit organisation and set delegation to give to some users the permission to edit all users in this OU.

We have a problem with some admin accounts. the delegation doesn't work.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,999 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,606 Reputation points
    2020-12-20T22:06:11.953+00:00

    Hi,

    Check if the inheritance option is enabled on the ACLs of admin accounts.

    Please don't forget to mark this reply as answer if it help you to fix your issue


2 additional answers

Sort by: Most helpful
  1. Fan Fan 15,306 Reputation points Microsoft Vendor
    2020-12-21T03:56:32.22+00:00

    Hi,

    It may caused by the Security Descriptor Propagator (SDPROP) if the user was in the protected group.
    This background process runs, by default, every sixty (60) minutes on the Domain Controller holding PDC Emulator FSMO role in an Active Directory domain.
    Even if you delegate (change) permissions on Domain Admins group, Active Directory will overwrite them by setting the ones used on AdminSDHolder container.
    Following link for your reference:
    https://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx

    Best Regards,

    1 person found this answer helpful.

  2. Dave Patrick 426.2K Reputation points MVP
    2020-12-20T22:04:26.783+00:00

    Maybe you can verify the permissions.
    https://social.technet.microsoft.com/wiki/contents/articles/6477.active-directory-how-to-view-or-delete-delegated-permissions.aspx

    --please don't forget to Accept as answer if the reply is helpful--