<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx</link><description>Ned here again. After a few years of supporting Active Directory, nearly everyone runs into an issue with AdminSdHolder . This object and its AD worker code is used by Domain Controllers to protect high-privilege accounts from inadvertent modification</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3239175</link><pubDate>Mon, 11 May 2009 23:40:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3239175</guid><dc:creator>AmyPadgett</dc:creator><description>&lt;p&gt;I've wrestled with this issue for a number of years. &amp;nbsp;I finally wrote up a tongue-in-cheek blog about it as a way to avoid a murder charge.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://enterpriseadminanon.blogspot.com/"&gt;http://enterpriseadminanon.blogspot.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Enjoy--Amy&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3239175" width="1" height="1"&gt;</description></item><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3239174</link><pubDate>Mon, 11 May 2009 23:40:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3239174</guid><dc:creator>AmyPadgett</dc:creator><description>&lt;p&gt;I've wrestled with this issue for a number of years. &amp;nbsp;I finally wrote up a tongue-in-cheek blog about it as a way to avoid a murder charge.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://enterpriseadminanon.blogspot.com/"&gt;http://enterpriseadminanon.blogspot.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Enjoy--Amy&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3239174" width="1" height="1"&gt;</description></item><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3237666</link><pubDate>Fri, 08 May 2009 16:59:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237666</guid><dc:creator>NedPyle [MSFT]</dc:creator><description>&lt;p&gt;Yep, I cannot get it to flip with just AdminCount=1 anymore. Nice catch Tony, I've updated that piece as well.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237666" width="1" height="1"&gt;</description></item><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3237647</link><pubDate>Fri, 08 May 2009 16:17:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237647</guid><dc:creator>NedPyle [MSFT]</dc:creator><description>&lt;p&gt;You are right about SDPROP - I was trying to oversimplify here without going into the actual undocumented worker that makes up AdminSDholder, but ended up making it sound like they were one in the same - in reality they are related, but only in passing. I've tweaked the article a bit to make more sense, let me know what you think.&lt;/p&gt;
&lt;p&gt;I'm trying out the AdminCount part right now in a repro. From looking at source code (rather than trusting an internal doc), I am beginning to suspect that you are right - once upon a time this might have been the case, but no longer since at least 2003. I'll change that part too if needed.&lt;/p&gt;
&lt;p&gt;Thanks Tony!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237647" width="1" height="1"&gt;</description></item><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3237640</link><pubDate>Fri, 08 May 2009 16:06:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237640</guid><dc:creator>Mike Kline</dc:creator><description>&lt;p&gt;Another good article Ned, I always wondered why the decision was made not to &amp;quot;decrement&amp;quot; AdminCount. &amp;nbsp;I see people on certain newsgroups confused because the accounts are no longer in a protected group.&lt;/p&gt;
&lt;p&gt;Another good blog entry on this subject is from Ulf Simon&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx"&gt;http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/05/29/49659.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Mike&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237640" width="1" height="1"&gt;</description></item><item><title>re: Five common questions about AdminSdHolder and SDProp</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3237352</link><pubDate>Fri, 08 May 2009 06:33:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237352</guid><dc:creator>murrato1</dc:creator><description>&lt;p&gt;Hi Ned&lt;/p&gt;
&lt;p&gt;Thanks for posting the article. &amp;nbsp;This an area that can, as you indicate, cause much confusion. &amp;nbsp;Just a couple of comments.&lt;/p&gt;
&lt;p&gt;1. &amp;nbsp;My understanding is that task that does the AdminSDHolder protection evaluation and sets the security descriptor on protected objects is not in fact SDPROP. &amp;nbsp;As far as I know there is no clear name for the task - I just call it &amp;quot;the AdminSDHolder task.&amp;quot; &amp;nbsp;Whenever a change is made to an object's security descriptor, SDPROP is invoked simply to propagate the changes to child objects. &amp;nbsp;In other words when objects are first protected by the AdminSDHolder task SDPROP is invoked, but doesn't really change anything (unless of course the object has child objects). &lt;/p&gt;
&lt;p&gt;This based on my understanding from an email conversation I had with someone knowledgeable a while back, so I could be wrong.&lt;/p&gt;
&lt;p&gt;2. You say...&amp;quot;since it's assumed that regardless of group membership, AdminCount being 1 should trigger protection.&amp;quot; &amp;nbsp;This does not appear to be the case. &amp;nbsp;If I set the adminCount value to 1 on an unprotected object it does not become protected on the next (hourly) cycle.&lt;/p&gt;
&lt;p&gt;Tony&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237352" width="1" height="1"&gt;</description></item><item><title>Ask the Directory Services Team : Five common questions about &amp;#8230; | Webmaster Tools</title><link>http://blogs.technet.com/b/askds/archive/2009/05/07/five-common-questions-about-adminsdholder-and-sdprop.aspx#3237235</link><pubDate>Fri, 08 May 2009 02:05:14 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3237235</guid><dc:creator>Ask the Directory Services Team : Five common questions about &amp;#8230; | Webmaster Tools</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.netdeluxo.com/blog/blogs/ask-the-directory-services-team-five-common-questions-about/"&gt;http://www.netdeluxo.com/blog/blogs/ask-the-directory-services-team-five-common-questions-about/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3237235" width="1" height="1"&gt;</description></item></channel></rss>