3ntity Posted September 16, 2015 Share Posted September 16, 2015 Hi,I've been doing quite a lot of scripting in AD using Water's AD UDF but I just can't seem to get my head around this one.I'm trying to change the ACL on an object in AD (Add Read-rights for a specific group on an object in an OU)In the object-properties I can find "nTSecurityDescriptor" but I don't see how to change the actual ACL ... (append, not overwrite)If anyone has any ideas to get me on the right path I'd be very much obliged. Thx. Link to comment Share on other sites More sharing options...
water Posted September 16, 2015 Share Posted September 16, 2015 Function _AD_EnablePasswordChange shows how to modify an ACL/ACE. At the moment there is no function to directly modify an ACL/ACE in the UDF. My UDFs and Tutorials: Spoiler UDFs:Active Directory (NEW 2022-02-19 - Version 1.6.1.0) - Download - General Help & Support - Example Scripts - WikiExcelChart (2017-07-21 - Version 0.4.0.1) - Download - General Help & Support - Example ScriptsOutlookEX (2021-11-16 - Version 1.7.0.0) - Download - General Help & Support - Example Scripts - WikiOutlookEX_GUI (2021-04-13 - Version 1.4.0.0) - DownloadOutlook Tools (2019-07-22 - Version 0.6.0.0) - Download - General Help & Support - WikiPowerPoint (2021-08-31 - Version 1.5.0.0) - Download - General Help & Support - Example Scripts - WikiTask Scheduler (NEW 2022-07-28 - Version 1.6.0.1) - Download - General Help & Support - Wiki Standard UDFs:Excel - Example Scripts - WikiWord - Wiki Tutorials:ADO - WikiWebDriver - Wiki Link to comment Share on other sites More sharing options...
3ntity Posted September 16, 2015 Author Share Posted September 16, 2015 Thanks, I'll check if that gets me where I need to be for now. (at least not having to use an external dsacls to get it done)Any chance this might get added into the UDF at some point ? Security on objects is quite useful in AD management (both get/set) for monitoring purposes etc. Link to comment Share on other sites More sharing options...
water Posted September 16, 2015 Share Posted September 16, 2015 I have checked the original ADFunctions UDF written by Jonathan Clelland but I couldn't find any functions to work with permissions.If you find any useful scripts written in Visual Basic I will be happy to translate them to AutoIt. My UDFs and Tutorials: Spoiler UDFs:Active Directory (NEW 2022-02-19 - Version 1.6.1.0) - Download - General Help & Support - Example Scripts - WikiExcelChart (2017-07-21 - Version 0.4.0.1) - Download - General Help & Support - Example ScriptsOutlookEX (2021-11-16 - Version 1.7.0.0) - Download - General Help & Support - Example Scripts - WikiOutlookEX_GUI (2021-04-13 - Version 1.4.0.0) - DownloadOutlook Tools (2019-07-22 - Version 0.6.0.0) - Download - General Help & Support - WikiPowerPoint (2021-08-31 - Version 1.5.0.0) - Download - General Help & Support - Example Scripts - WikiTask Scheduler (NEW 2022-07-28 - Version 1.6.0.1) - Download - General Help & Support - Wiki Standard UDFs:Excel - Example Scripts - WikiWord - Wiki Tutorials:ADO - WikiWebDriver - Wiki Link to comment Share on other sites More sharing options...
AdamUL Posted September 16, 2015 Share Posted September 16, 2015 Check out the Set ACL Permissions UDF, it may be able to help you. I have never tried to use it with AD, but from looking at the UDF, there is are object types that are available. $SE_DS_OBJECT, _;Indicates a directory service object or a property set or property of a directory service object. e.g.CN=SomeObject,OU=ou2,OU=ou1,DC=DomainName,DC=CompanyName,DC=com,O=internet $SE_DS_OBJECT_ALL, _;Indicates a directory service object and all of its property sets and properties. Also the ACL in nTSecurityDescriptor is written in Security Descriptor Definition Language (SDDL). Hopefully that will give you a start. Adam Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now