Default NTFS permissions too liberal on newly created volumes
- From: "Mike M" <nospam@xxxxxxxxxx>
- Date: Sun, 22 Jan 2006 20:58:17 -0600
Windows 2003 SP1 server here...
I created a folder called "public" under the z:\ drive, shared it as
"public", and verified that all users in my department had read-only
permissions via a certain group. All seemed well until I saw legit data
folders popping up in this shared folder that was allegedly read-only save
for the admins. The user was able to create folders and files in the public
share that was supposed to be read-only!!!
Well...
It seems to me that configuring a secondary volume, named as Drive Z:,
brings liberal permissions to the root of the drive for the USERS group.
Drilling down into the advanced security settings window shows 3 separate
entries for the local-server\USERS group:
--Read & Execute, This folder, subfolders and files
--Create Folders/Append Data, This folder and subfolders
--Create Files / Write Data, Subfolders only
I looked at the other servers that we've built and all have the same
all-too-liberal permission settings for the USERS group. It seems to me
that USERS can do everything but delete files by default.
Why is Microsoft allowing the USERS group such liberal permissions by
default? It was a no-brainer to remove the EVERYONE group to tighten
things up, but this issue seems to make things more difficult to lock-down
security on file servers. Am I missing something???
TIA,
Mike
.
- Follow-Ups:
- Re: Default NTFS permissions too liberal on newly created volumes
- From: BerkHolz, Steven
- Re: Default NTFS permissions too liberal on newly created volumes
- From: Roger Abell [MVP]
- Re: Default NTFS permissions too liberal on newly created volumes
- From: Ondrej Sevecek
- Re: Default NTFS permissions too liberal on newly created volumes
- From: Steven L Umbach
- Re: Default NTFS permissions too liberal on newly created volumes
- Prev by Date: Delegation problem
- Next by Date: Re: Default NTFS permissions too liberal on newly created volumes
- Previous by thread: Delegation problem
- Next by thread: Re: Default NTFS permissions too liberal on newly created volumes
- Index(es):
Relevant Pages
|