Fix Active Directory broken security inheritance problem

Ran into a situation at a client location where in Active Directory, the security permissions applied to an OU were not getting inherited permissions on to the objects. Basically, security inheritance was broken.This causes a problem when the administrative accounts or groups needing to modify an attribute on the AD object throw errors, or are unable to edit the AD object.

To find out which objects were not getting the inherited permissions run the following :

I ran it on the entire domain to identity potential problem accounts. 🙂

To fix the issue:


DNS broken after Windows Update KB3145126

I noticed the DNS broke on my servers after Windows Update.

The problem was KB3145126. Read more about it here.

After a quick removal and reboot, DNS was operational again.

To remove/uninstall KB3145126, open powershell and run the following:

Hope this helps.