Do all login users secretly belong to the Users group?

From: sparky62 (sparky62_at_discussions.microsoft.com)
Date: 05/12/05


Date: Thu, 12 May 2005 11:24:04 -0700

I create a new user, make it a member of the Guests group and explicitly
remove it
from the Users group (so that the new user is a member of the Guests group
and no other group).

Strangely this new user has the "effective permissions" to "read & execute"
a file as if it was in the Users group. This is very odd behaviour.

My file has an ACL with "full control" ACEs for
SYSTEM, Administrators and CURRENT OWNER (Administrator), and a "read &
execute" ACE for the "Users" group (and no other ACEs).

Also if I log on as the new user in the Guests group I can read the file too.

What is going on?



Relevant Pages

  • Re: Do all login users secretly belong to the Users group?
    ... > I create a new user, make it a member of the Guests group and explicitly ... > from the Users group (so that the new user is a member of the Guests group ... > execute" ACE for the "Users" group (and no other ACEs). ...
    (microsoft.public.win2000.security)
  • Why does a user ONLY in the Guests group have Users permissions?
    ... If I create a new user and make it a member of the Guests group and remove it ... group) how come the new user has the "effective permissions" to a file system ... and no other ACEs. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Access is Denied to Event Viewer logs
    ... Also open the local guests group, ... Access is Denied to Event Viewer logs ... | I am afraid the Administrator is not a member of the Guest group. ...
    (microsoft.public.win2000.security)
  • Re: Anonymous user access problem.
    ... is the new Test user a memberof USERS group? ... > was not able to access ftp server using anonymous user. ... > and made it member of guests group only and I am able to access FTP site ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Anonymous user access problem.
    ... Yes the new Test user is just member of Guests group only. ... >> was not able to access ftp server using anonymous user. ...
    (microsoft.public.inetserver.iis.ftp)

Quantcast