The ACL permission of DFS folders is reset after DFS Namespace service restart in Windows Server 2008 R2
Scenario:
we have a lot of DFS namespaces shared across on our domain, reachable via\\example.com\namespace1 and \\example.com\namespace2. DFS namespaces has ABE enabled. After a reboot of a domain controller all namespaces are available through that server except for the content of the ABE enabled namespaces. After I import the NTFS rights again with ICACLS or FileACL the content is available again. If we do another reboot or rest the permission the process starts over again.
Cause:
This issue occurs because of a logic error in the DFS Namespace service. This issue occurs when the service sets an Access Control List (ACL) to the DFS folders in a DFS version 1 namespace during the service start-up process.
Resolution:
Installation of hotfix KB2464365 was carried out and the issue was no longer experienced.
Hotfix Download:
https://support.microsoft.com/kb/2464365
Comments