|
|
|
|
Active Directory Extended Rights
While standard operations on objects stored in and protected by Active Directory are governed by standard Active Directory permissions, there are certain operations that have special significance, and require special or extended permissions for their authorization.
These special or extended permissions govern the ability of a user to perform specific Active Directory operations, or Active Directory based identity and access management operations, and are often referred to as Active Directory Extended Rights.
The Active Directory security model recognizes fifty-one extended rights –
Abandon-Replication
Add-GUID
Allocate-Rids
Allowed-To-Authenticate
Apply-Group-Policy
Certificate-Enrollment
Change-Domain-Master
Change-Infrastructure-Master
Change-PDC
Change-Rid-Master
Change-Schema-Master
Create-Inbound-Forest-Trust
Do-Garbage-Collection
Domain-Administer-Server
DS-Check-Stale-Phantoms
DS-Execute-Intentions-Script
DS-Install-Replica
DS-Query-Self-Quota
DS-Replication-Get-Changes
DS-Replication-Get-Changes-All
DS-Replication-Manage-Topology
DS-Replication-Monitor-Topology
DS-Replication-Synchronize
Enable-Per-User-Reversibly-Encrypted-Password
Generate-RSoP-Logging
Generate-RSoP-Planning
Migrate-SID-History
msmq-Open-Connector
msmq-Peek
msmq-Peek-computer-Journal
msmq-Peek-Dead-Letter
msmq-Receive
msmq-Receive-computer-Journal
msmq-Receive-Dead-Letter
msmq-Receive-journal
msmq-Send
Open-Address-Book
Read-Only-Replication-Secret-Synchronization
Reanimate-Tombstones
Recalculate-Hierarchy
Recalculate-Security-Inheritance
Receive-As
Refresh-Group-Cache
SAM-Enumerate-Entire-Domain
Send-As
Send-To
Unexpire-Password
Update-Password-Not-Required-Bit
Update-Schema-Cache
User-Change-Password
User-Force-Change-Password
|
|