Error: Security Descriptor on the directory server could not be modified. (NETIQKB54020)

  • 7754020
  • 02-Feb-2007
  • 19-Jun-2007

Resolution

fact
Directory and Resource Administrator 7.5

symptom
Error: "Security Descriptor on the directory server could not be modified."

symptom
Error: "Could not modify security descriptor" when attempting to create or clone a user account.

symptom
When creating or cloning a user account, the home directory is created, however, the permissions on the directory have inherited permissions, and the newly-created user ACE does not get set. 

cause

An issue with the DACL and out-of-order ACEs causes Windows to create an excessive number of duplicate ACEs and exceed the size limitation for DRA.



fix

To resolve this problem:

  1. Locate the directory in Windows Explorer.
  2. Right click the directory and select Properties.
  3. On the Security tab, add a new dummy trustee and click Apply.
  4. Remove the dummy trustee and click Apply.

During the process of applying the new security, native tools should automatically remove any ACEs detected as duplicates.



note
You can use a tool DumpSec to diagnose this problem. Download DumpSec from the following url:  http://www.systemtools.com/somarsoft/

Additional Information

Formerly known as NETIQKB54020