You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've noticed a weird issue which I've been trying to solve for quite some time.
On one specific account, the owner of this object was updated to another group "Domain Admins", but PingCastle reports that the old groups still have Full rights.
I have used different tools to list all permissions, inherited or not, but cannot find why this is being reported by your tool.
Hopefully, I am not missing something obvious here :)
The text was updated successfully, but these errors were encountered:
Hi there, thank you for the extra information and the report here! I have reproduced the issue but I cannot seem to immediately track down where exactly the bug is here but it is obvious that there is an issue with nested permissions vs adminsdholder protection (or just specific object permissions) and seems like it may be based on the container_hierarchy section not excluding objects that do not have inheritance enabled.
We will add this to the backlog and aim to fix this in the next 3.4 version. Will keep you updated.
Hello,
I've noticed a weird issue which I've been trying to solve for quite some time.
On one specific account, the owner of this object was updated to another group "Domain Admins", but PingCastle reports that the old groups still have Full rights.
I have used different tools to list all permissions, inherited or not, but cannot find why this is being reported by your tool.
Hopefully, I am not missing something obvious here :)
The text was updated successfully, but these errors were encountered: