How is write access to system only attributes enforced?

in researching changes our password policy, came across documentation on pwdlastset attribute. admin can set 0 or -1 regardless of tool use edit (powershell, adsi edit, etc.). out of curiosity, looked @ attributes of of attribute , didn't glean useful.

how domain service know attributes enforce in fasion , how know valid values are?

justin cervero - ms enterprise admin - appalachian state university

this hardcoded in dsa (ntdsa.dll) contains list of allowed/disallowed modifications - attributes owned sam (security account manager) , listed in samsrv.dll - there nothing can changes those.

enfo zipper
christoffer andersson – principal advisor - directory services blog

Windows Server  >  Directory Services


Popular posts from this blog

Cannot access Anywhere Access using domain name?

server manager error: could not be enumerated.

send messages to users