Re: Authenticated users question
From: GRCC (grccnews_at_nospamadelphia.net)
Date: 07/28/04
- Previous message: Dave W.: "Re: Computer Management Security Question"
- In reply to: Rick A. Butler: "Re: Authenticated users question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 28 Jul 2004 16:25:57 -0400
Hey Rick,
Thanks. That helps . I removed the authenticated users from the data folders
and replaced them with the groups and/or people who need access. We only
have one server, som I have to use it as the file server.
Thanks again,
Frank
"Rick A. Butler" <orion2634@yahoo.com> wrote in message
news:%23g9piACdEHA.3392@tk2msftngp13.phx.gbl...
> GRCC -
>
> Assuming the data folders you're talking about are folders you created,
you
> are correct. If you have a file folder that's listing 'Authenticated
Users'
> for full control rights, that means anyone who can log onto the server,
> whether it be local or domain, would have FC on that folder. Since this is
a
> DC, users logging on through AD apply here. (yeah, there are builtin
> users/groups, but often, they are not used on a DC)
>
> Full Control rights are hardly necessary on data folders. You only need to
> assign FC if you have people who need to assign permissions or take
> ownership. If all they need to do is Read, Write, Execute, or Delete, then
> set their effective permission to modify. In most cases, unless there is a
> general access need, you should prolly not even assign permissions to
> Authenticated Users, but rather, specify groups, assign personnel with
need
> to know to those groups and give that group the permission it needs.
>
> Additionally, unless there is a specific need to share files from your DC,
> I'd recommend not using your DC for file services, especially if you only
> have one DC in your domain/forest.
>
> HTH -
>
> Rick A. Butler
>
>
> "GRCC" <grccnews@nospamadelphia.net> wrote in message
> news:elKD7JBdEHA.1604@TK2MSFTNGP11.phx.gbl...
> > Dumb question probably, sorry. Authenticated Users have full control in
> > some data folders on our w2k domain controller. Is this neccesary?
> Wouldn't
> > that mean all users who are auhenticated have full control, which would
be
> > all users? Authenticated Users somewhat confusing.
> > Thanks
> > GRCC
> >
> >
>
>
- Previous message: Dave W.: "Re: Computer Management Security Question"
- In reply to: Rick A. Butler: "Re: Authenticated users question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|