<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="https://wiki.ledhed.net/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.ledhed.net/index.php?action=history&amp;feed=atom&amp;title=Domain_Admin_User_Permission_Inheritance</id>
		<title>Domain Admin User Permission Inheritance - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.ledhed.net/index.php?action=history&amp;feed=atom&amp;title=Domain_Admin_User_Permission_Inheritance"/>
		<link rel="alternate" type="text/html" href="https://wiki.ledhed.net/index.php?title=Domain_Admin_User_Permission_Inheritance&amp;action=history"/>
		<updated>2026-04-16T21:54:47Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.2</generator>

	<entry>
		<id>//wiki.ledhed.net/index.php?title=Domain_Admin_User_Permission_Inheritance&amp;diff=2905&amp;oldid=prev</id>
		<title>Ledhed at 20:46, 23 August 2013</title>
		<link rel="alternate" type="text/html" href="https://wiki.ledhed.net/index.php?title=Domain_Admin_User_Permission_Inheritance&amp;diff=2905&amp;oldid=prev"/>
				<updated>2013-08-23T20:46:05Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:46, 23 August 2013&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I came across a strange behavior the other day. I delegated control of &amp;quot;Reset Password&amp;quot; to a group of helpdesk users.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;I came across a strange behavior the other day. I delegated control of &amp;quot;Reset Password&amp;quot; to a group of helpdesk users.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;My initial testing seemed to imply that the delegation didn't work. Turns out that I was testing the password reset on a user object that was previously a member of the 'Domain Admins' group.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;My initial testing seemed to imply that the delegation didn't work. Turns out that I was testing the password reset on a user object that was previously a member of the 'Domain Admins' group.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The reason this is significant is that Microsoft removes permission inheritance on any user object that is a member of the 'Domain Admins' group. This is a feature in that it prevents users with lower permissions from resetting passwords on 'Domain Admin' users.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The reason this is significant is that Microsoft removes permission inheritance on any user object that is a member of the 'Domain Admins' group. This is a &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;great &lt;/ins&gt;feature in that it prevents users with lower permissions from resetting passwords on 'Domain Admin' users.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ledhed</name></author>	</entry>

	<entry>
		<id>//wiki.ledhed.net/index.php?title=Domain_Admin_User_Permission_Inheritance&amp;diff=2904&amp;oldid=prev</id>
		<title>Ledhed: Created page with &quot;I came across a strange behavior the other day. I delegated control of &quot;Reset Password&quot; to a group of helpdesk users. My initial testing seemed to imply that the delegation di...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.ledhed.net/index.php?title=Domain_Admin_User_Permission_Inheritance&amp;diff=2904&amp;oldid=prev"/>
				<updated>2013-08-23T20:45:30Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;I came across a strange behavior the other day. I delegated control of &amp;quot;Reset Password&amp;quot; to a group of helpdesk users. My initial testing seemed to imply that the delegation di...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;I came across a strange behavior the other day. I delegated control of &amp;quot;Reset Password&amp;quot; to a group of helpdesk users.&lt;br /&gt;
My initial testing seemed to imply that the delegation didn't work. Turns out that I was testing the password reset on a user object that was previously a member of the 'Domain Admins' group.&lt;br /&gt;
The reason this is significant is that Microsoft removes permission inheritance on any user object that is a member of the 'Domain Admins' group. This is a feature in that it prevents users with lower permissions from resetting passwords on 'Domain Admin' users.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here in the interesting part,  Microsoft does not reset the user object properties to inherit permissions once the user object is removed from the 'Domain Admins' group.&lt;br /&gt;
This means that any former Domain Admin user will not be able to have their password reset by users that have been delegated control.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The solution is go to the the Security Tab of the user object, click Advanced, and click Reset to Defaults button (or check the Inherit check box).&lt;br /&gt;
If you can't see the security tab for the user, then on &amp;quot;Active Directory Users and Computers&amp;quot; click the view menu and check &amp;quot;Advanced Features&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Windows]]&lt;/div&gt;</summary>
		<author><name>Ledhed</name></author>	</entry>

	</feed>