s4: don't forget to update defaultSecurityDescriptor