If inheritance is broken at the OU level, re-enable it on the OU so domain or parent OU permissions can flow down to newly created accounts.
Steps in Active Directory Users and Computers:
- Open Active Directory Users and Computers.
- Locate the affected OU.
- Right-click the OU and select Properties.
- Open Security > Advanced.
- If Enable Inheritance is shown, select it.
- Verify inheritance is also enabled on every parent OU or container above it, because permissions must cascade from the domain level down to the target OU.
Expected result:
- Baseline permissions inherited from the parent hierarchy become applicable to the OU.
- Newly created accounts in that OU can inherit those permissions.
If the issue involves protected accounts or groups, note that protected objects have inheritance disabled by design through AdminSDHolder. In that case, either:
- ensure the affected users are not members of protected groups, or
- if inheritance must be restored broadly for protected objects, inheritance can be enabled on the adminSDHolder container using Active Directory Users and Computers or ADSI Edit.
To enable inheritance on adminSDHolder in Active Directory Users and Computers:
- In View, enable Advanced Features.
- Go to CN=adminSDHolder,CN=System,DC=<MyDomain>,DC=<Com>.
- Right-click the container and select Properties.
- Open Security > Advanced.
- Select Allow Inheritable permissions to propagate to this object and all child objects.
- Select OK and Close.
Important: Enabling inheritance on adminSDHolder changes the protection model for members of protected groups. The change can take up to 60 minutes to be applied by SDProp and additional time to replicate.
A safer alternative for protected accounts is to remove users from protected groups when appropriate, then reset inheritance for accounts that are no longer supposed to remain protected.