Displaying 1 result from an estimated 1 matches for "se_dacl_auto_inherited".
2024 May 16
1
Security descriptors options of Group Policies
Hi Samba List, hope you're doing well all.
We have realized a security
audit of our Samba4 Active Directory.
It returns that the security
descriptors options of all our GPO objects are wrong. They should be :
SE_DACL_AUTO_INHERITED
SE_DACL_PRESENT
instead of this, the options
are by default :
SE_DACL_PROTECTED
SE_DACL_PRESENT
We can change the
options, but the "sysvolreset" command of samba-tool revert our changes
at every run. (BTW we use sysvolreset because "sysvolcheck" returns
errors after each GP...