Re: Repost: Using SetTokenInformation to control file system virtualization on Vista?



Hi Jordan,

Thanks for your patient.

Below is the feedback information I got from one of the Vista security
developer:

1. Nope. SetTokenInformation() is already a high-level API :)

2. That's the only effect, but note that you're dancing on the edge of
what's supported when you tinker with a process's virtualization state.
Virtualization is intended as a bridge technology that we will remove in
the future once enough applications work without needing its assistance
(ideally Windows 8, but we'll see), so there are no guarantees with what
will happen if you build in assumptions on it (though the API and infolevel
will always be there). For example, the call will have no effect in a
process where virtualization cannot be enabled (e.g., a process with an
application manifest that specifies a "requestedExecutionLevel").

3. Yes, 0 and 1 are the actual values.

4. Nope -- virtualization is explicitly disabled under impersonation, so
the setting is ignored in the thread token (i.e., process token only).

Below is some more information:

For both file and registry virtualization, we disable virtualization for
the call if the thread effective token type is not TokenPrimary. Given the
final design, it probably makes more sense to simply query the process
token. We will look into this.

Hope this helps.

Best regards,
Jeffrey Tan
Microsoft Online Community Support
==================================================
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications.

Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.
==================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

.



Relevant Pages

  • Re: Repost: Using SetTokenInformation to control file system virtualization on Vista?
    ... global namespace but instead getting the virtual file? ... This is embedding specific knowledge about virtualization in your ... Microsoft Online Community Support ... where an initial response from the community or a Microsoft Support ...
    (microsoft.public.platformsdk.security)
  • Re: Repost: Using SetTokenInformation to control file system virtualization on Vista?
    ... Would separating the user data migration functionality into a separate ... those user files that it has access while virtualization is enabled. ... Microsoft Online Community Support ... where an initial response from the community or a Microsoft Support ...
    (microsoft.public.platformsdk.security)
  • Re: Need Expert Opinions - VMware & Active Directory
    ... They can't tell them they can't do it but by the same token those companies can't tell MSFT that they have to support it. ... The very best support on non-MSFT virtualization is best effort and you have to duplicate the issue on physical hardware if they so decide. ... Simply put, if you blow your physical host, you aren't just restoring the host and restarting VMs from the restored host's disk... ...
    (microsoft.public.windows.server.active_directory)
  • RE: Exchange 2003 installation on VMWARE virtual machine.
    ... Running Microsoft Exchange Server in a Virtual Machine Using VMware ESX ... Microsoft Support Policies and Recommendations for Exchange Servers in ... Hardware Virtualization Environments ...
    (microsoft.public.exchange.setup)
  • Re: PC Shopping: How do I tell if a PC is VT-capable (MS Virtualization)?
    ... How is it Intel's fault that you purchased a PC that doesn't support virtualization? ... Will a "Windows 7 ready" sticker, if such exists, include VT ... "AMD markets its virtualization extensions to the 64-bit x86 architecture ...
    (microsoft.public.windowsxp.hardware)

Quantcast