RBAC Inheritance Broken on Active Directory OU

Emma Brooks 0 Reputation points
2026-09-30T16:07:30.6033333+00:00

Newly created accounts in an OU fail to inherit baseline security permissions. How do we re-enable permission inheritance using Active Directory tools?

Windows for business | Windows 365 Enterprise
0 comments No comments

2 answers

Sort by: Most helpful
  1. James Gamble 170 Reputation points
    2026-09-30T17:58:43.9966667+00:00

    Hola Emma,

    Check the affected user object and the OU, because enabling inheritance on the OU won't restore it for a user whose own inheritance is disabled. In Active Directory Users and Computers, select View > Advanced Features, then open the affected user's Properties > Security > Advanced. If Enable inheritance is displayed, inheritance is currently disabled. For an ordinary, nonprotected account, select it and Apply, then confirm that the expected entries appear with an "Inherited from" source.

    If inheritance is already enabled, check the parent OU for the missing permission under Properties > Security > Advanced. Its "Applies to" scope must include the relevant user objects; an entry scoped to "This object only" won't reach newly created users. Microsoft explains object-specific inheritance here.

    I'd avoid changing AdminSDHolder as suggested in the automated answer. It's the permissions template for protected accounts across the domain, so changing it can affect privileged-account security well beyond this OU. If inheritance becomes disabled again, check whether the user belongs directly or through nested groups to a protected group, such as Domain Admins or Account Operators.

    Which specific permission is missing, and does the affected user's Advanced Security window show "Enable inheritance" or "Disable inheritance"? That will help distinguish blocked inheritance from an incorrectly scoped delegation.

    Thanks,

    James

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-30T16:07:48.8266667+00:00

    If inheritance is broken at the OU level, re-enable it on the OU so domain or parent OU permissions can flow down to newly created accounts.

    Steps in Active Directory Users and Computers:

    1. Open Active Directory Users and Computers.
    2. Locate the affected OU.
    3. Right-click the OU and select Properties.
    4. Open Security > Advanced.
    5. If Enable Inheritance is shown, select it.
    6. Verify inheritance is also enabled on every parent OU or container above it, because permissions must cascade from the domain level down to the target OU.

    Expected result:

    • Baseline permissions inherited from the parent hierarchy become applicable to the OU.
    • Newly created accounts in that OU can inherit those permissions.

    If the issue involves protected accounts or groups, note that protected objects have inheritance disabled by design through AdminSDHolder. In that case, either:

    • ensure the affected users are not members of protected groups, or
    • if inheritance must be restored broadly for protected objects, inheritance can be enabled on the adminSDHolder container using Active Directory Users and Computers or ADSI Edit.

    To enable inheritance on adminSDHolder in Active Directory Users and Computers:

    1. In View, enable Advanced Features.
    2. Go to CN=adminSDHolder,CN=System,DC=<MyDomain>,DC=<Com>.
    3. Right-click the container and select Properties.
    4. Open Security > Advanced.
    5. Select Allow Inheritable permissions to propagate to this object and all child objects.
    6. Select OK and Close.

    Important: Enabling inheritance on adminSDHolder changes the protection model for members of protected groups. The change can take up to 60 minutes to be applied by SDProp and additional time to replicate.

    A safer alternative for protected accounts is to remove users from protected groups when appropriate, then reset inheritance for accounts that are no longer supposed to remain protected.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.