2003 home folder security problem

From: Dan King (danking65_at_earthlink.net)
Date: 08/06/04


Date: Thu, 5 Aug 2004 17:46:26 -0700

There seems to be a lack of security in the 2003 version of Active
Directories Users and Computers (ADUC).
When creating a home folder with the 2000 version of ADUC, the home folder
rights given are:
Adminstrators - FULL CONTROL
and
the user FULL CONTROL.

It then makes it so rights are not inherited from the parent folder.
The 2003 version of ADUC gives the same rights, but does NOT prevent the
inheritance of rights.

So a default home folder created by the 2000 ADUC is secure,
and the default home folder created by the 2003 ADUC is NOT secure. Giving
all Domain Users READ access.

The OS that the folder is being created on does not matter, only the ADUC
version used.

Does anyone know of a fix for this, or is having the same experience?
A possible fix is to go to every home folder and uncheck rights inheritance,
but that can be tedious. It seems MS took a step back in security here.

Dan

-- 
   __o
 _-\<,
(_)/(_)____


Relevant Pages

  • 2003 home folder security problem
    ... There seems to be a lack of security in the 2003 version of Active ... Directories Users and Computers (ADUC). ... When creating a home folder with the 2000 version of ADUC, ... It then makes it so rights are not inherited from the parent folder. ...
    (microsoft.public.windows.server.general)
  • Re: 2003 home folder security problem
    ... inheriting permissions is not a security problem. ... permissions on the parent folder where users home folder are created so any ... Directories Users and Computers (ADUC). ... It then makes it so rights are not inherited from the parent folder. ...
    (microsoft.public.win2000.security)
  • Re: 2003 home folder security problem
    ... Does that happen when a regular user creates the folder as well? ... > Directories Users and Computers (ADUC). ... > When creating a home folder with the 2000 version of ADUC, ... > It then makes it so rights are not inherited from the parent folder. ...
    (microsoft.public.windows.server.general)
  • Re: Home Folder Owner
    ... folder owner is Administrators but when you create the same home folder on ... the same share with ADUC 2000 it assigns the folder owner as the user? ... How do you create the Home folder do you setup the home folder under user ... the same share with ADUC 2000 it assigns the folder owner as the user?(The ...
    (microsoft.public.windows.server.active_directory)
  • Re: access denied issue
    ... Users evrything but full control ... Security is the same as on the "D" security ... with the individual user and administrators as full control ... Each user *must* have at least write access to not only his/her home folder, ...
    (microsoft.public.windows.server.security)

Loading