Re: Access denied on GPO after "ntacl sysvolreset"

Klaas TJEBBES via samba <[email protected]> Tue, 14 Apr 2026 14:16:46 +0200
Newsgroups gmane.network.samba.general
Message-ID <a3b285ef-dede-452d-93d4-9b86fddc82f8@region-academique-bourgogne-franche-comte.fr>

Le 14/04/2026 à 13:24, Rowland Penny via samba a écrit :
> On Tue, 14 Apr 2026 11:51:27 +0200
> Klaas TJEBBES via samba <[email protected]> wrote:
> 
>> root@addc:~# samba-tool ntacl get
>> "/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}/Machine/Preferences"
>> --as-sddl
>> O:DAG:DAD:(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;;FA;;;DA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;;;AU)(A;OICI;0x1200a9;;;ED)
> 
> That is the correct ACL and if we break it down, it becomes:
> 
> O:LA
> G:BA
> D:P
> (A;OICI;FA;;;BA)
> (A;OICI;0x1200a9;;;SO)
> (A;OICI;FA;;;SY)
> (A;OICI;0x1200a9;;;AU)
> 
> A brief explanation of what that all means:
> 
> The owner is 'LA'
> The group is 'BA'
> The DACL is PROTECTED
> Each individual ACE is surrounded by a pair of braces '(.....)' and each ACE is separated by commas.
> 
> In the ACES:
> A = ACCESS_ALLOWED
> OI = OBJECT_INHERIT
> CI = CONTAINER_INHERIT
> FA = FILE_ALL
> 0x1200a9 = GRGX
> GR = GENERIC_READ
> GX = GENERIC_EXECUTE
> 
> LA = LOCAL_ADMIN
> BA = BUILTIN_ADMINISTRATORS
> SO = SERVER_OPERATORS
> SY = LOCAL_SYSTEM
> AU = AUTHENTICATED_USERS
> 
> So from that, Windows sees the file ownership as
> LOCAL_ADMIN:BUILTIN_ADMINISTRATORS and on a Samba AD DC they are mapped
> to the root user & group, but beware, you will come across GPOs owned
> by Domain Admins (O:DA) which is a group. Windows sees that members of
> the Administrators group are allowed access with full control, members
> of the Server Operators group (SID S-1-5-32-549) are allowed access with
> read & execute permissions, The local system (i.e. the computer)  is
> allowed access with full control and Authenticated Users are allowed
> access with read & execute permissions.
> 
> I hope you understand this so far.
> 
> The thing is, when you use Samba with Extended Attributes, Samba takes
> the standard Unix 'ugo' permissions and any permissions you set via
> setfacl into account and tries to alter the permissions that windows
> sees in its EA. It also takes into account anything you add to a share,
> this one of the reasons why you should not add anything to a share on a
> Samba AD DC (including the netlogon and sysvol shares) and why you
> really should set permissions from a Windows machine.
> 
> Each directory under 'sysvol' has it own set of ACEs and these are the
> ones that you should be looking at with samba-tool and you should
> ignore the ouput of ls and getfacl and you should definitely never
> attempt to set permissions on anything under 'sysvol' with setfacl.
> 
> There is also the problem of idmap.ldb , this is where Samba 'maps'
> SIDs to Unix IDs, usually in the '3000000' range unless you add RFC2307
> attributes (and I am less & less convinced you need them, Samba like
> Windows really uses the SID). The main problem is that Samba maps the
> SIDs on a first come basis and you cannot guarantee that they will turn
> up in exactly the same order on each DC, hence a user or group can have
> a different Unix ID on each DC unless you copy idmap.ldb from your
> first DC to any others.
> 
> Any questions ?

Yes.

I have only one DC.

I did :
* remove all ACLs and default ACLs on /var/lib/samba/sysvol/ (setfacl 
-Rbk /var/lib/samba/sysvol/)
* chown root:root /var/lib/samba/sysvol/ -R
* samba-tool ntacl sysvolreset

Then I went to my GPO and tried to add a .INI File preference. It still 
failed with "Acccess denied".

So I checked Windows ACLs :
root@addc:~# samba-tool ntacl get --as-sddl 
/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{168E5E09-529C-4947-84BE-DD3410700CBE\}/Machine/Preferences
O:DAG:DAD:(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;;FA;;;DA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;;;AU)(A;OICI;0x1200a9;;;ED)

root@addc:~# samba-tool ntacl get --as-sddl 
/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{168E5E09-529C-4947-84BE-DD3410700CBE\}
O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;OICI;0x1200a9;;;ED)

root@addc:~# samba-tool ntacl get --as-sddl 
/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{168E5E09-529C-4947-84BE-DD3410700CBE\}/Machine
O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;OICI;0x1200a9;;;ED)

 From Windows, when I right clic => Properties => Security on the 
"Preferences" folder of the GPO, I get : "the requested security 
information is not available or cannot be displayed".


What am I missing ?

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba