Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-9489: Permission of deleting AD computer object using adleave

Centrify DirectControl ,  

22 November,17 at 09:33 AM

Applies to: Suite 2017.1 and later versions of Centrify DirectControl 

Problem: 

The upgraded adclient 5.4.1 a.k.a Suite 2017.1 has problem to remove AD computer object out from AD infrastructure with command 'adleave -r -u <delegated user>' executed, even the <delegated user> has "Delete Computer Objects" permission granted on AD computer container.

Cause: 

The LDAP flag used in the DELETE request sent to AD is changed to 
LDAP_SERVER_TREE_DELETE_OID, and LDAP_SERVER_EXTENDED_DN_OID was used in old times. 

The LDAP_SERVER_TREE_DELETE_OID control is used with an extended LDAP delete function to delete an entire subtree in the directory

Hence "Delete subtree" right to Descendant Computer object on the container/OU that the computer object locate is also needed.

Workaround: 

Both "Delete subtree" and "Delete compute objects" permissions are required to remove a computer object with adleave command.

References: (provided as a courtesy) 
https://msdn.microsoft.com/en-us/library/aa366991(v=vs.85).aspx
http://ijustdoit.eu/ad-delegate-permissions-to-add-delete-move-computer-objects

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.