Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DSREVOKE is a legacy Windows command-line utility for reporting or removing permissions that a named user or group has on organizational units (OUs) in Active Directory. The safest approach is to report and review the explicit permission entries first, then remove only the entries you have confirmed are in scope. Microsoft’s published requirements cover Windows 2000, Windows XP Professional, and Windows Server 2003, with Windows 2000 or Windows Server 2003 domain controllers as targets; support on current Windows releases is not established.

What DSREVOKE does—and what it does not do

Microsoft describes DSREVOKE as a command-line tool that reports permissions for a specified user or group on a set of OUs and can optionally remove that principal’s permissions from those OUs’ discretionary access control lists (DACLs). It complements the Delegation of Control Wizard: the wizard delegates administrative authority, while DSREVOKE provides a way to revoke delegated authority. Microsoft Download Center: DSREVOKE.EXE.

Its documented scope is OU permissions assigned to a named user or group. Do not treat it as a general-purpose editor for every Active Directory ACL or as a complete audit of all objects and naming contexts.

Compatibility and version context

Microsoft’s download page identifies DSREVOKE as version 1.0 and lists Windows 2000, Windows XP, and Windows Server 2003 as supported operating systems. It specifies Windows 2000 and Windows Server 2003 Active Directory domain controllers as targets. The page’s publication date is July 15, 2024, but that date is page metadata, not evidence that the utility has been maintained for modern Windows versions. Do not infer current Windows support from it. Microsoft Download Center.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to report permissions before removing them

Use a report-first workflow and verify the target before making a change. Microsoft’s instructions call for running the utility on a Windows 2000, Windows XP, or Windows Server 2003 domain member or controller in the forest being targeted. Those are the environments named in its published requirements, not a recommendation to introduce an obsolete system into a current environment.

  1. Use a role-specific security group. Microsoft recommends a unique security group for each specific administrative role and delegation through OU inheritance. This makes the intended principal and role easier to identify when reviewing delegated permissions. Microsoft Download Center.
  2. Check the utility’s syntax. From a command prompt in the documented environment, run DSREVOKE /? and consult the supplied documentation for the exact syntax and prompts. Microsoft Download Center.
  3. Generate a report. Microsoft specifically describes using /report to verify explicit permissions for a role group on OU objects. A technical walkthrough gives this illustrative form: Dsrevoke /Report OU=NewYork,DC=Contoso,DC=Com ContosoEd.Price. The domain and user are examples, not values to copy into your environment. KAK / Kornev Online walkthrough.
  4. Inspect the reported entries and intended scope. The walkthrough shows checking an ACE in Active Directory Users and Computers (ADUC). To see an OU’s Security tab and Advanced Security Settings, enable View > Advanced Features in ADUC, then inspect the OU’s security settings. Compare the reported principal, permissions, and OU with the change you intend to make. KAK / Kornev Online walkthrough.
  5. Remove only after review. The walkthrough illustrates removal with Dsrevoke /Remove OU=NewYork,DC=Contoso,DC=Com ContosoEd.Price. Treat this as an example, verify the command syntax and any prompts against the utility’s documentation, and confirm the principal and OU scope before proceeding. KAK / Kornev Online walkthrough.

A report is a useful review step, but the available documentation does not establish that it is a complete audit of every permission on every type of Active Directory object. Do not use it as proof that all delegated access across a directory has been found.

Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reported limitations and alternatives

A 2019 secondary technical article reports that DSREVOKE may find no more than 1,000 OUs in one search and may fail when an OU name contains a forward slash. These are reported limitations, not details stated on Microsoft’s download page; investigate the documented behavior in the relevant environment before relying on a search result. HeelpBook: Active Directory Delegated Permissions (View/Remove).

The same article describes dsacls.exe as able to remove delegated permissions, but says it does not search subcontainers in the way DSREVOKE does. The cited material does not establish a broader compatibility comparison or a preview workflow for dsacls, so choose and validate a method based on the precise target and scope rather than assuming the tools are interchangeable. HeelpBook.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s Revoke-DfsrDelegation cmdlet is not a general replacement: it revokes delegated permissions for users or groups on a DFS Replication group, a distinct, narrower operation. Microsoft Learn: Revoke-DfsrDelegation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.