JSI Tip 6399. How can I modify Active Directory object attributes, like the defaultSecurityDescriptor?

Microsoft Knowledge Base Article 265399 contains the following summary:

This step-by-step article describes how to modify Active Directory object attributes. The example in this article changes the defaultSecurityDescriptor attribute of the Organizational Unit object to remove the Read permission from the members of the Authenticated Users group.

Caution Microsoft recommends that you use caution if you modify the Active Directory schema. This operation is an advanced operation that is best performed programmatically by experienced programmers and system administrators. For detailed information about how to modify the Active Directory schema, see the Active Directory Programmer's Guide. To do so, visit the following Microsoft Web site:


Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.