Effective Permissions displays incorrect information

Posted by Konrads on Server Fault See other posts from Server Fault or by Konrads
Published on 2012-07-04T08:36:09Z Indexed on 2012/07/10 9:17 UTC
Read the original article Hit count: 252

I have a security mystery :) Effective permissions tab shows that a few sampled users (IT ops) have any and all rights (all boxes are ticked). The permissions show that Local Administrators group has full access and some business users have too of which the sampled users are not members of. Local Administrators group has some AD IT Ops related groups of which the sampled users, again, appear not be members. The sampled users are not members of Domain Administrators either. I've tried tracing backwards (from permissions to user) and forwards (user to permission) and could not find anything. At this point, there are three options:

  • I've missed something and they are members of some groups.
  • There's another way of getting full permissions.
  • Effective Permissions are horribly wrong.

Is there a way to retrieve the decision logic of Effective Permissions? Any hints, tips, ideas?

UPDATE: The winning answer is number 3 - Effective Permissions are horribly wrong. When comparing outputs as ran from the server logged on as admin and when running it as a regular user from remote computer show different results: All boxes (FULL) access and on server - None. Actually testing the access, of course, denies access.

© Server Fault or respective owner

Related posts about active-directory

Related posts about permissions