Re: security INF files

From: Nick Finco [MSFT] (nfinco_at_online.microsoft.com)
Date: 12/05/03


Date: Fri, 5 Dec 2003 14:37:42 -0800

Localization issues.

No, setting "XYZ__memberof=" won't search out all the groups that XYZ is a
member of and remove it. If there is a list of groups, the account will be
added to those groups. Then if you are running XP or WS2003 and you remove
a group from the memberof list, XYZ would be removed from the group so the
setting doesn't tattoo. That's the only scenario which would cause XYZ to
be removed from a group.

N

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
Any opinions or policies stated within are my own and do not necessarily
constitute those of my employer.  Use of included script samples are subject
to the terms specified at http://www.microsoft.com/info/cpyright.htm
"randy" <rgoebel@yahoo.com> wrote in message
news:0d5501c3bad7$095387b0$a001280a@phx.gbl...
> Why would they do that instead of just calling
> it "guest_members"?
>
> Would it be safe then to assume that "*S-1-5-32-
> 547__Memberof=" will remove power users from every group
> they are a member of?
>
> Thanks again.
>
> :Randy
> >-----Original Message-----
> >That will remove all accounts from the power users group.
> >
> >Lower down in the template you should see a Strings
> section where this is
> >defined:  SceInfGuests = "Guests"  The line you
> mentioned would remove all
> >accounts from the guests group.
> >
> >N
> >
> >-- 
> >This posting is provided "AS IS" with no warranties, and
> confers no rights.
> >Any opinions or policies stated within are my own and do
> not necessarily
> >constitute those of my employer.  Use of included script
> samples are subject
> >to the terms specified at
> http://www.microsoft.com/info/cpyright.htm
> >
> >
> ><rgoebel@yahoo.com> wrote in message
> >news:0bb901c3b0a3$6748fbe0$a001280a@phx.gbl...
> >> I found "*S-1-5-32-547__Memberof=" and "*S-1-5-32-
> >> 547__Members ="in several INF files for securing your
> >> servers.  However, I cannot verify what they are for.
> >>
> >> I assume this removes the power users from any group
> and
> >> removes them from being memebers of any groups.  Is
> there
> >> a document or some place I can verify this?
> >>
> >>
> >> SECOND,
> >> What is "%SceInfGuests%__Members ="?
> >>
> >> :Randy
> >
> >
> >.
> >


Relevant Pages

  • Re: AD Delegation Fails - Permissions Disappear
    ... in turn a member of the Print Operators group. ... inheriting permissions?? ... ACL on all security principals (users, groups, and machine accounts) present ... AdminSDHolder Object Affects Delegation of Control for Past Administrator ...
    (microsoft.public.windows.server.active_directory)
  • Question regarding New User Creation Script
    ... to manage both the NT4 domain and the AD Domain. ... use the VBScript I have created to create user accounts they can only ... create accounts on the NT4 domain and not the AD domain. ... the script directly on a server which is a member of the AD domain ...
    (microsoft.public.scripting.vbscript)
  • Re: User Login
    ... filtering so that only this group gets the deny logon locally privilegs. ... the domain group called Domain Users is a member of the local ... put those user accounts into domain group and apply a GPO to the OU ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Filtering Dimensions using Cube Roles
    ... In the allowed member list for the role you can put a MDX statement ... This will return a set of accounts which have "Branch20" in the Branch ... > where each level has a member property called "Branch". ...
    (microsoft.public.sqlserver.datawarehouse)
  • Re: Restricting Local User Account
    ... Members of the Administrators group can fully administer user accounts; only Administrators can assign user rights and access privileges for resources. ... Members of the Power Users group can create accounts only in the Power Users, Users, and Guests groups; they can also maintain and delete the accounts they create. ... A member of the Users group can create, maintain, and delete accounts in local groups that he or she has created. ...
    (microsoft.public.win2000.general)