This question comes up so often I decided to write a little something something on it so I can point people at it instead of rewriting the answer. So let’s say the questions comes in like Question: How do I query AD for all users (or objects or whatever) that don’t have “Allow inheritable permissions […]