Re: Share and NTFS permissions



No security risk other than someone screwing up and not setting the NTFS permissions properly.

As for why they have both mechanisms, because if they didn't, you would have 100 people in here at least including myself asking why MSFT didn't give that flexibility. Maybe you have a situation where regardless of anything, no one should have more than READ when connecting through a specific share (say it is a share that houses archive data) but some admin screws up when adding a new folder to it and gives Change... The Share RO permissions would make that case so it wasn't an issue.

It really isn't all that confusing. I think when I first heard about it back in about 1995 or 1996 I spent all of about 15 seconds thinking about it and haven't had an issue since. Doesn't mean I haven't seen hundreds if not thousands of admins have issues with it. But that doesn't make me question the granularity capability in the system.



--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


vashi wrote:
I have read that the best way to allocate permissions for shared folders is - is to Share the folder . Give Share-Permissions as " Everyone Full Control" and give the specific Allow/Deny permissions in the NTFS tab.

Is there any insecurity in giving Share-permissions as Full control and only specifying the NTFS permissions accurately ?

If no insecurities , why is Windows giving us the facility to give permissions in 2 places and making it confusing?

.



Relevant Pages

  • Re: NTFS and shared permissions
    ... > I have a few questions about NTFS permissions and share that I hope ... I know that NTFS permissions are applied to ... NTFS permissions are of course needed for control of accounts ... down from a more broad NTFS grant). ...
    (microsoft.public.security)
  • Re: Need Help on Assigning Specific Permissions to Shares
    ... can not be changed which would leave only ntfs permissions to control ... in groups to have necessary ntfs permissions. ... XP uses simple file sharing by default. ... > XP Pro but it doesn't say it works in Home edition. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Migrating File servers
    ... shared permissions separately. ... For NTFS permissions, we can use the Windows 2000 Resource Kit tool ... Copy all the data from the old file server to target file server. ...
    (microsoft.public.windows.server.migration)
  • Re: recovering NTFS volumes
    ... If ntfs permissions are not being copied when data is backed up then I believe it ... If the files did not include the administrators group ... but instead a user/group unique to the operating system that is was backed up from, ...
    (microsoft.public.win2000.security)
  • Re: Local Group Restricted to Internet Explorer Browser only
    ... combination of group policy, group membership, and ntfs permissions. ... permissions by themselves can control access fairly well to installed ... applications and data that reside in root or program files folder. ...
    (microsoft.public.win2000.security)