3.3.5.3 GPO Property Update

Whenever an administrative tool modifies the properties of the abstract element Administered GPO, it produces the LDAP modifyRequest message (as defined in the specification of the GPO Property Update Message section 2.2.8.3) from the client to the server.

If the value of the modifyResponse message's resultCode is integer 0, it indicates success. Any other resultCode value indicates a failure.

When the nTSecurityDescriptor attribute is modified in the GPO Property Update Message (section 2.2.8.3), the following file access message is included in the GPO Property Update message:

Modify the security descriptor on the directory to the value of the nTSecurityDescriptor GPO attribute using an implementation-specific method.<25>

The GPO File System Version Update (section 3.3.5.4) file access messages make up the remainder of the GPO Property Update message.