Manually initializing the SD propagator thread to evaluate inherited permissions for objects in Active Directory (251343)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server
This article was previously published under Q251343 SUMMARY Microsoft Windows NT 4.0 and earlier protects the users in
administrative groups by changing the Access Control List (ACL) on the members
as they are added to the groups. Windows 2000 uses a different method to
accommodate support for nested groups and universal groups. Windows 2000
supports universal groups, which can have members in other domains and could
themselves be members of groups in other domains.
Windows 2000 uses
the SD propagator (SDPROP) background process to implement the protection of
administrative groups. This process first computes the set of memberships in
transitive fashion for all administrative groups. It then walks the list of
objects that it has and checks whether the security descriptor on the objects
is a well-known protected security descriptor. If the well-known protected
security descriptor is not set, it sets this security descriptor on the object.
This task runs only on the primary domain controller Flexible Single Master
Operation (FSMO) role holder.
Modification Type: | Minor | Last Reviewed: | 7/12/2004 |
---|
Keywords: | kbenv kbhowto KB251343 |
---|
|