Resolution
fact
Directory and Resource Administrator 7.5
symptom
Error: "Security Descriptor on the directory server could not be modified."
symptom
Error: "Could not modify security descriptor" when attempting to create or clone a user account.
symptom
When creating or cloning a user account, the home directory is created, however, the permissions on the directory have inherited permissions, and the newly-created user ACE does not get set.
cause
fix
note
You can use a tool DumpSec to diagnose this problem. Download DumpSec from the following url: http://www.systemtools.com/somarsoft/
Directory and Resource Administrator 7.5
symptom
Error: "Security Descriptor on the directory server could not be modified."
symptom
Error: "Could not modify security descriptor" when attempting to create or clone a user account.
symptom
When creating or cloning a user account, the home directory is created, however, the permissions on the directory have inherited permissions, and the newly-created user ACE does not get set.
cause
An issue with the DACL and out-of-order ACEs causes Windows to create an excessive number of duplicate ACEs and exceed the size limitation for DRA.
fix
To resolve this problem:
- Locate the directory in Windows Explorer.
- Right click the directory and select Properties.
- On the Security tab, add a new dummy trustee and click Apply.
- Remove the dummy trustee and click Apply.
During the process of applying the new security, native tools should automatically remove any ACEs detected as duplicates.
note
You can use a tool DumpSec to diagnose this problem. Download DumpSec from the following url: http://www.systemtools.com/somarsoft/
Additional Information
Formerly known as NETIQKB54020