Skip to content

Invoke-DMAccessRule alternative Domainmanagement.AccessRules.Remove.Option2 #71

@dbeugger

Description

@dbeugger

Hi
ADMF can not remove ACEs from AD Computer objects I'm getting follwing warnings:
WARNING: [15:59:56][Invoke-DMAccessRule] Failed to removing access rule for "SecurityPrinzipal" , granting WriteProperty (Allow) from "DnComputerObject" for unknown reasons (sorry). If this persists, consider enabling the alternative deletion mode through the "Domainmanagement.AccessRules.Remove.Option2" configuration setting.
I can remove the ACEs by hand without problems.
The ACEs on the object were created when the computer joined the domain. The security principal is the account that performed the join. It is also the owner of the computer. Changing the owner of the object does not change this behavior.

What can i do?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions