Re: Access denied on GPO after "ntacl sysvolreset"

Klaas TJEBBES via samba <[email protected]> Tue, 14 Apr 2026 11:51:27 +0200
Newsgroups gmane.network.samba.general
Message-ID <aad956a6-ad58-42b4-abac-3df7ab6c79c1@region-academique-bourgogne-franche-comte.fr>

Le 13/04/2026 à 18:35, Rowland Penny via samba a écrit :
> On Mon, 13 Apr 2026 17:35:11 +0200
> Klaas TJEBBES via samba <[email protected]> wrote:
> 
>> Hello.
>>
>> I come back on the subject because the problem is still present.
>>
>> For information :
>> Ubuntu 24.04.4 LTS
>> samba 2:4.19.5+dfsg-4ubuntu9.4
>>
>> /etc/samba/smb.conf
>>
>> [global]
>>     realm = DOMSCRIBE.AC-TEST.FR
>>     workgroup = DOMSCRIBE
>>     netbios name = ADDC
>>     disable netbios = yes
>>     smb ports = 445
>>     map acl inherit = Yes
>>     store dos attributes = Yes
>>     winbind separator = /
>>     server role = active directory domain controller
>>     server services = -dns
>>     tls enabled = yes
>>     tls keyfile = /var/lib/samba/private/tls/key.pem
>>     tls certfile = /var/lib/samba/private/tls/cert.pem
>>     tls cafile =
>>     usershare max shares = 0
>>     restrict anonymous = 2
>>     interfaces = 192.168.0.30
>>     log level = 3
>>
>> [netlogon]
>>     comment = Network Logon Service
>>     path = /home/sysvol/domscribe.ac-test.fr/scripts
>>     read only = No
>>     guest ok = yes
>>
>> [sysvol]
>>     comment = Sysvol Service
>>     #path = /home/sysvol
>>     path = /var/lib/samba/sysvol
>>     read only = No
>>     guest ok = yes
>>     inherit acls = yes
>>
>>
>> The user I'm doing all the action with on the Windows side is :
>> root@addc:~# id admin
>> uid=3000026(DOMSCRIBE/admin) gid=100(users)
>> groupes=100(users),3000026(DOMSCRIBE/admin),3000027(DOMSCRIBE/professeurs),3000004(DOMSCRIBE/domain
>> admins),3000005(DOMSCRIBE/denied rodc password replication
>> group),3000009(BUILTIN/users),3000000(BUILTIN/administrators)
>>
>>
>> Sympoms :
>> * create a GPO on Windows 11 RSAT
>> * run 'samba-tool ntacl sysvolreset'
>> * trying to modify GPO in RSAT returns an "Access Denied" error.
>>
>> It has to deal with sub-directory created with faulty ACLs. For
>> example, after creating an empty GPO, I have :
>>
>> root@addc:~# tree
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/
>> ├── GPT.INI
>> ├── Machine
>> └── User
>>
>> root@addc:~# getfacl
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/
>> getfacl : suppression du premier « / » des noms de chemins absolus
>> # file:
>> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/
>> # owner: BUILTIN/administrators
>> # group: users
>> user::rwx
>> user:NT\040Authority/system:rwx
>> user:NT\040Authority/authenticated\040users:r-x
>> user:DOMSCRIBE/domain\040admins:rwx
>> user:DOMSCRIBE/enterprise\040admins:rwx
>> user:NT\040Authority/enterprise\040domain\040controllers:r-x
>> group::---
>> group:users:---
>> group:BUILTIN/administrators:rwx
>> group:NT\040Authority/system:rwx
>> group:NT\040Authority/authenticated\040users:r-x
>> group:DOMSCRIBE/domain\040admins:rwx
>> group:DOMSCRIBE/enterprise\040admins:rwx
>> group:NT\040Authority/enterprise\040domain\040controllers:r-x
>> mask::rwx
>> other::---
>> default:user::rwx
>> default:user:BUILTIN/administrators:rwx
>> default:user:NT\040Authority/system:rwx
>> default:user:NT\040Authority/authenticated\040users:r-x
>> default:user:DOMSCRIBE/domain\040admins:rwx
>> default:user:DOMSCRIBE/enterprise\040admins:rwx
>> default:user:NT\040Authority/enterprise\040domain\040controllers:r-x
>> default:group::---
>> default:group:users:---
>> default:group:NT\040Authority/system:rwx
>> default:group:NT\040Authority/authenticated\040users:r-x
>> default:group:DOMSCRIBE/domain\040admins:rwx
>> default:group:DOMSCRIBE/enterprise\040admins:rwx
>> default:group:NT\040Authority/enterprise\040domain\040controllers:r-x
>> default:mask::rwx
>> default:other::---
>>
>>
>> Then I run 'samba-tool ntacl sysvolreset' and I get :
>>
>> root@addc:~# getfacl
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/
>> getfacl : suppression du premier « / » des noms de chemins absolus
>> # file:
>> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/
>> # owner: DOMSCRIBE/domain\040admins
>> # group: DOMSCRIBE/domain\040admins
>> user::rwx
>> user:root:rwx
>> user:BUILTIN/administrators:rwx
>> user:BUILTIN/server\040operators:r-x
>> user:NT\040Authority/system:rwx
>> user:NT\040Authority/authenticated\040users:r-x
>> group::rwx
>> group:BUILTIN/administrators:rwx
>> group:BUILTIN/server\040operators:r-x
>> group:NT\040Authority/system:rwx
>> group:NT\040Authority/authenticated\040users:r-x
>> mask::rwx
>> other::---
>> default:user::rwx
>> default:user:root:rwx
>> default:user:BUILTIN/administrators:rwx
>> default:user:BUILTIN/server\040operators:r-x
>> default:user:NT\040Authority/system:rwx
>> default:user:NT\040Authority/authenticated\040users:r-x
>> default:group::---
>> default:group:BUILTIN/administrators:rwx
>> default:group:BUILTIN/server\040operators:r-x
>> default:group:NT\040Authority/system:rwx
>> default:group:NT\040Authority/authenticated\040users:r-x
>> default:mask::rwx
>> default:other::---
>>
>> Then in RSAT I do :
>> Computer => Preferences => Windows Parameters => .ini files =>
>> C:\test.ini (section a, key b, value c) => Click OK
>>
>> It returns the error "Access denied", and indeed, this INI File
>> creation action in RSAT, creates a sub-directory named "Preferences"
>> and its ACLs are faulty :
>>
>> root@addc:~# getfacl
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/
>> getfacl : suppression du premier « / » des noms de chemins absolus
>> # file:
>> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/
>> # owner: BUILTIN/administrators
>> # group: users
>> user::rwx
>> user:root:rwx                   #effective:r-x
>> user:BUILTIN/administrators:rwx #effective:r-x
>> user:BUILTIN/server\040operators:r-x
>> user:NT\040Authority/system:rwx #effective:r-x
>> user:NT\040Authority/authenticated\040users:r-x
>> group::---
>> group:BUILTIN/administrators:rwx        #effective:r-x
>> group:BUILTIN/server\040operators:r-x
>> group:NT\040Authority/system:rwx        #effective:r-x
>> group:NT\040Authority/authenticated\040users:r-x
>> mask::r-x
>> other::---
>> default:user::rwx
>> default:user:root:rwx
>> default:user:BUILTIN/administrators:rwx
>> default:user:BUILTIN/server\040operators:r-x
>> default:user:NT\040Authority/system:rwx
>> default:user:NT\040Authority/authenticated\040users:r-x
>> default:group::---
>> default:group:BUILTIN/administrators:rwx
>> default:group:BUILTIN/server\040operators:r-x
>> default:group:NT\040Authority/system:rwx
>> default:group:NT\040Authority/authenticated\040users:r-x
>> default:mask::rwx
>> default:other::---
>>
>> and :
>>
>> root@addc:~# tree
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/
>> ├── GPT.INI
>> ├── Machine
>> │   ├── Preferences
>> │   └── Scripts
>> └── User
>>
>>
>> So I re-run 'samba-tool ntacl sysvolreset', and retry create INI file
>> in RSAT, again an "Access denied" error, but this time a new
>> sub-directory has been created :
>>
>> root@addc:~# tree
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/
>> ├── GPT.INI
>> ├── Machine
>> │   ├── Preferences
>> │   │   └── IniFiles
>> │   └── Scripts
>> └── User
>>
>> But, again, it has faulty ACLs :
>>
>> root@addc:~# getfacl
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/
>> getfacl : suppression du premier « / » des noms de chemins absolus
>> # file:
>> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/
>> # owner: DOMSCRIBE/domain\040admins
>> # group: DOMSCRIBE/domain\040admins
>> user::rwx
>> user:root:rwx
>> user:BUILTIN/administrators:rwx
>> user:BUILTIN/server\040operators:r-x
>> user:NT\040Authority/system:rwx
>> user:NT\040Authority/authenticated\040users:r-x
>> group::rwx
>> group:BUILTIN/administrators:rwx
>> group:BUILTIN/server\040operators:r-x
>> group:NT\040Authority/system:rwx
>> group:NT\040Authority/authenticated\040users:r-x
>> mask::rwx
>> other::---
>> default:user::rwx
>> default:user:root:rwx
>> default:user:BUILTIN/administrators:rwx
>> default:user:BUILTIN/server\040operators:r-x
>> default:user:NT\040Authority/system:rwx
>> default:user:NT\040Authority/authenticated\040users:r-x
>> default:group::---
>> default:group:BUILTIN/administrators:rwx
>> default:group:BUILTIN/server\040operators:r-x
>> default:group:NT\040Authority/system:rwx
>> default:group:NT\040Authority/authenticated\040users:r-x
>> default:mask::rwx
>> default:other::---
>>
>> root@addc:~# getfacl
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/IniFiles/
>> getfacl : suppression du premier « / » des noms de chemins absolus
>> # file:
>> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/IniFiles/
>> # owner: BUILTIN/administrators
>> # group: users
>> user::rwx
>> user:root:rwx                   #effective:r-x
>> user:BUILTIN/administrators:rwx #effective:r-x
>> user:BUILTIN/server\040operators:r-x
>> user:NT\040Authority/system:rwx #effective:r-x
>> user:NT\040Authority/authenticated\040users:r-x
>> group::---
>> group:BUILTIN/administrators:rwx        #effective:r-x
>> group:BUILTIN/server\040operators:r-x
>> group:NT\040Authority/system:rwx        #effective:r-x
>> group:NT\040Authority/authenticated\040users:r-x
>> mask::r-x
>> other::---
>> default:user::rwx
>> default:user:root:rwx
>> default:user:BUILTIN/administrators:rwx
>> default:user:BUILTIN/server\040operators:r-x
>> default:user:NT\040Authority/system:rwx
>> default:user:NT\040Authority/authenticated\040users:r-x
>> default:group::---
>> default:group:BUILTIN/administrators:rwx
>> default:group:BUILTIN/server\040operators:r-x
>> default:group:NT\040Authority/system:rwx
>> default:group:NT\040Authority/authenticated\040users:r-x
>> default:mask::rwx
>> default:other::---
>>
>> If I re-re-run 'samba-tool ntacl sysvolreset', then this time, it's
>> OK, RSAT is happy and I have this :
>>
>> root@addc:~# tree
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/
>> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/
>> ├── GPT.INI
>> ├── Machine
>> │   ├── Preferences
>> │   │   └── IniFiles
>> │   │       └── IniFiles.xml
>> │   └── Scripts
>> └── User
>>
>>
>> As you can see, the problem is the "mask::r-x" that is put on the
>> newly created directory. Each time "sysvolreset" puts it back to
>> "mask::rwx" but the it's the new sub-directory that gets a wrong
>> "mask". And so on until the last directory needed to store the file
>> containing the GPO parameter.
>>
>> It's as if, in one way or the other, default ACLs are not correctly
>> inherited.
>>
>>
>> What am I missing ? or is there really a bug in "sysvolreset" ?
>>
>> Thank you.
>>
>>
>> Le 17/04/2025 à 15:54, Klaas TJEBBES via samba a écrit :
>>> We https://pcll.ac-dijon.fr/pcll/ are editor of servers from the
>>> French Ministry of Education. We provide Samba servers, Firewalls,
>>> VPN aggregators and monitoring servers since more that 20 years.
>>> These servers are for schools, administrations, etc. We have 18000
>>> servers in production, that means approximately 6 million users.
>>>
>>> Historically we have always stored users data in /home. Since the
>>> path of [sysvol] is configurable, we have put it in /home as well.
>>>
>>> For example, on the file server, the one that hosts people
>>> homedirs, those dirs are stored in /home/adhomes/<username>, group
>>> dirs are stored in /home/workgroups/<groupname>, recycle bin in
>>> /home/recycle, etc.
>>>
>>> This simplifies a lot server partitioning and backups. For example
>>> /home can be put on a faster device than /, or one can decide to
>>> put /home on a SAN with persistent data while / is a VM image, etc.
>>>
>>>
>>> But I doubt putting [sysvol] in /home has something to do with the
>>> problem we are facing :
>>> * 'samba-tool ntacl sysvolcheck' does not detect that ACLs are wrong
>>> * 'samba-tool ntacl sysvolreset' does not place the same ACLs as
>>> Windows does and this leads to prevent importing GPO parameters in
>>> RSAT.
>>>
>>> Also I don't understand your sentence "Why are sysvol and netlogon
>>> in / home instead of being in /var/lib/samba where it belongs ?".
>>>
>>> Can you explain what the technical problem is to put [sysvol]
>>> elsewhere ? I've taken a look to samba source code and could find
>>> any answer to this question.
>>>
>>>
>>>
>>> Also can you confirm that on your setup, which you told has the
>>> same ACLs than the one that are problematic for me, you can import
>>> parameters from a previously backuped GPO in RSAT ? see image
>>> https://ibb.co/QvFkV8nW
>>>
>>>
>>>
>>> Le 16/04/2025 à 18:07, Rowland Penny via samba a écrit :
>>>> On Wed, 16 Apr 2025 17:03:10 +0200
>>>> Klaas TJEBBES via samba <[email protected]> wrote:
>>>>
>>>>>
>>>>> I don't understand how import parameters from a previously
>>>>> backuped GPO in RSAT can work on your setup as it clearly does
>>>>> not on ours.
>>>>>
>>>>>
>>>>> To summarize :
>>>>>
>>>>> root@addc:~# cat /etc/lsb-release
>>>>> DISTRIB_ID=Ubuntu
>>>>> DISTRIB_RELEASE=24.04
>>>>> DISTRIB_CODENAME=noble
>>>>> DISTRIB_DESCRIPTION="Ubuntu 24.04.2 LTS"
>>>>>
>>>>> root@addc:~# cat /etc/samba/smb.conf
>>>>> [global]
>>>>>      realm = DOMSCRIBE.AC-TEST.FR
>>>>>      workgroup = DOMSCRIBE
>>>>>      netbios name = ADDC
>>>>>      disable netbios = yes
>>>>>      smb ports = 445
>>>>>      map acl inherit = Yes
>>>>>      store dos attributes = Yes
>>>>>      winbind separator = /
>>>>>      server role = active directory domain controller
>>>>>      server services = -dns
>>>>>      tls enabled = yes
>>>>>      tls keyfile = /var/lib/samba/private/tls/key.pem
>>>>>      tls certfile = /var/lib/samba/private/tls/cert.pem
>>>>>      tls cafile =
>>>>>      usershare max shares = 0
>>>>>      restrict anonymous = 2
>>>>>      interfaces = 192.168.0.30
>>>>>
>>>>> [netlogon]
>>>>>      comment = Network Logon Service
>>>>>      path = /home/sysvol/domscribe.ac-test.fr/scripts
>>>>>      read only = No
>>>>>      guest ok = yes
>>>>>
>>>>> [sysvol]
>>>>>      comment = Sysvol Service
>>>>>      path = /home/sysvol
>>>>>      read only = No
>>>>>      guest ok = yes
>>>>>
>>>>
>>>> I asked this once, but you didn't answer, lets try again:
> 
> Lets try again, why is netlogon not where it supposed to be ?
> I notice you have put sysvol back to where it should be.
> 
> Why have you added things to netlogon & sysvol even though the Samba
> wiki tells you not to ?
> 
> Finally, why are you ignoring the EA that stores the Windows ACEs that
> are set by creating the GPOs, try running:
> 
> sudo samba-tool ntacl get /var/lib/samba/sysvol --as-sddl
> 
> The output of the above command is the permissions that count, not
> the standard Unix permissions or the output of getfacl, though they will
> affect the permissions, as will adding things to the netlogon & sysvol
> shares.
>   
> Rowland
> 
> 

Sorry, "netlogon" was an error. I've fixed it.

[global]
   realm = DOMSCRIBE.AC-TEST.FR
   workgroup = DOMSCRIBE
   netbios name = ADDC
   disable netbios = yes
   smb ports = 445
   map acl inherit = Yes
   store dos attributes = Yes
   winbind separator = /
   server role = active directory domain controller
   server services = -dns
   tls enabled = yes
   tls keyfile = /var/lib/samba/private/tls/key.pem
   tls certfile = /var/lib/samba/private/tls/cert.pem
   tls cafile =
   usershare max shares = 0
   restrict anonymous = 2
   interfaces = 192.168.0.30
   log level = 3

[netlogon]
   comment = Network Logon Service
   path = /var/lib/samba/sysvol/domscribe.ac-test.fr/scripts
   read only = No
   guest ok = yes

[sysvol]
   comment = Sysvol Service
   #path = /home/sysvol
   path = /var/lib/samba/sysvol
   read only = No
   guest ok = yes
   inherit acls = yes
   inherit owner = yes


root@addc:~# samba-tool ntacl get /var/lib/samba/sysvol --as-sddl
O:LAG:BAD:P(A;OICI;FA;;;BA)(A;OICI;0x1200a9;;;SO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)


New GPO created with RSAT has :

root@addc:~# samba-tool ntacl get 
"/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}" 
--as-sddl
O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(A;OICI;0x1200a9;;;ED)


New GPO after "sysvolreset" :

root@addc:~# samba-tool ntacl get 
"/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}" 
--as-sddl
O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;OICI;0x1200a9;;;ED)


And after trying to add a .INI File preference in RSAT (which failed 
with "Access Denied" error) :

root@addc:~# samba-tool ntacl get 
"/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}/Machine/Preferences" 
--as-sddl
O:DAG:DAD:(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;;FA;;;DA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;;;AU)(A;OICI;0x1200a9;;;ED)



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba