Knowledge Base

PRB: SetUserObjectSecurity Returns ERROR_NOT_ENOUGH_QUOTA

Article ID: 185292

Article Last Modified on 11/21/2006


APPLIES TO


This article was previously published under Q185292

SYMPTOMS

SetUserObjectSecurity returns:
ERROR_NOT_ENOUGH_QUOTA

CAUSE

All Microsoft Windows NT, Windows 2000, Windows XP Executive objects, which Window stations and Desktops belong to, have a 2K limit on Access Control Lists (ACL). SetUserObjectSecurity returns ERROR_NOT_ENOUGH_QUOTA when this limit is reached. This 2K limit equals approximately 84 or 85 Access Control Entries (ACE).

RESOLUTION

It is recommended that you add an ACE based on the Logon Security Identifier (SID) since this duplicates the process used by the system. For more information on doing this, please see the following article in the Microsoft Knowledge Base:

165194 INFO: CreateProcessAsUser, Windowstations and Desktops

Consider the following options when you experience this problem:

STATUS

This behavior is by design.

Additional query words: kbDSupport kbdss kbKernBase kbSecurity

Keywords: kbapi kbfaq kbkernbase kbprb kbsecurity KB185292