RE: XCACLS.VBS

From: Steve Dodson [MSFT] (stevedod_at_online.microsoft.com)
Date: 06/24/04


Date: Thu, 24 Jun 2004 15:00:07 GMT

Keith,

Subinacl is a great tool to use to grant or deny users permissions to a
particular folder in the filesystem. You can download it at the following
location:

http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-
93cf-ed6985e3927b&displaylang=en

Hope that helps!

Steve Dodson [MSFT]
PSS Security
MCSE, CISSP

-- 
This posting is provided "AS IS" with no warranties, and confers no rights. 
Use of included script samples are subject to the terms specified at 
http://www.microsoft.com/info/cpyright.htm 
Note:  For the benefit of the community-at-large, all responses to this 
message are best directed to the newsgroup/thread from which they 
originated.  
--------------------
>Content-Class: urn:content-classes:message
>From: "Keith Wiedemann" <anonymous@discussions.microsoft.com>
>Sender: "Keith Wiedemann" <anonymous@discussions.microsoft.com>
>Subject: XCACLS.VBS
>Date: Wed, 23 Jun 2004 10:05:29 -0700
>Lines: 14
>Message-ID: <20c2201c45944$490ddcf0$a001280a@phx.gbl>
>MIME-Version: 1.0
>Content-Type: text/plain;
>	charset="iso-8859-1"
>Content-Transfer-Encoding: 7bit
>X-Newsreader: Microsoft CDO for Windows 2000
>X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4910.0300
>Thread-Index: AcRZREkNJ/BX2z14SA+hHjtXgioaAA==
>Newsgroups: microsoft.public.win2000.security
>Path: cpmsftngxa10.phx.gbl
>Xref: cpmsftngxa10.phx.gbl microsoft.public.win2000.security:28652
>NNTP-Posting-Host: tk2msftngxa08.phx.gbl 10.40.1.160
>X-Tomcat-NG: microsoft.public.win2000.security
>
>Does anyone have a copy of the VBScript that extends the 
>capability of XCACLS.EXE?
>
>I need to set explicit deny special access permissions 
>across several hundred directories, and I'd like to do it 
>through a batch file, but the EXE version only allows you 
>to GRANT special access, the VBS allows you to DENY it.
>
>I'd greatly appreciate it!
>
>You can send it to keith.wiedemann [AT] digitalnet.com
>
>(make sure to modify the extension so it doesn't get 
>stripped)
>


Relevant Pages

  • Re: do allowed perrmisions override denyed permissions?
    ... I thought deny access was more of a useful way to do things *TO* them! ... only grant permissions. ... | Explicit Grant ACEs for Object | ... to sort that out is with hierarchical precedence of the inheritance ...
    (microsoft.public.windows.server.security)
  • Re: do allowed perrmisions override denyed permissions?
    ... >> override the deny. ... But consider if you have the Deny on L1 and the Grant on L2... ... The only way to sort that out is with hierarchical precedence of the inheritance which is represented by the ordering of the ACEs in the ACL. ... The categories are inherited or explicit. ...
    (microsoft.public.windows.server.security)
  • Re: Denny SYNCHRONIZE to IUSR_%COMPUTERNAME% causes remote access to prompt for username
    ... [Ramon...on behalf of Luis García] ... If I deny write access from xcacls.vbs and after I grant read access, ... SYNCHRONIZE is still dennied, and IIS doesn't work. ...
    (microsoft.public.inetserver.iis.security)
  • Re: NTFS woes
    ... An explicit deny overrules and explicit or inherited grant. ... no permissions on those things to delete them. ...
    (microsoft.public.windows.server.security)
  • Re: controlling deleting of files with NTFS
    ... Hence when on this dir you deny delete to a group, ... grant delete to a user that is in the denied group, ... have (i.e. remove delete in the advanced view in the NTFS permissions ... On the top most folder I am trying to set the ntfs security on, ...
    (microsoft.public.security)