Re: Minimum NTFS Permissions on the SystemDrive
- From: "Steven L Umbach" <n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 11 May 2006 13:17:33 -0500
Well it depends. Generally Windows 2003/XP Pro have fairly restrictive
default settings for NTFS with the exception that users may be able to
create folders and write files to folders they create in the root folder.
You can remove that by looking in the advanced security tab of security for
the root folder. Users will have full control to their user profile folder
under documents and settings and have the ability to write to the shared
documents folder in the all users profile. The Windows folder is pretty
restrictive already and I recommend not to modify permissions there for
default groups other than individual files you may not want users to access
such as operating system command line tools. Program files will not allow
regular users to write to it but they may be able to run applications
installed in it. In general users will have read/list/execute to all folders
other then other users profile folders. The link below may be of help
explaining how to configure your operating system for principle of least
privilege for users. --- Steve
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/luawinxp.mspx
<skhair@xxxxxxxxxxxxx> wrote in message
news:1147363824.786947.294060@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,
What are the minimum permissions that should be applied to;
1) The root of the system drive (e.g. c:\)
2) The Windows folder
3) The Program files directory
4) Any other important directories
Thanks in advance for any help.
.
- References:
- Minimum NTFS Permissions on the SystemDrive
- From: skhair
- Minimum NTFS Permissions on the SystemDrive
- Prev by Date: Re: Minimum NTFS Permissions on the SystemDrive
- Next by Date: Re: RMS
- Previous by thread: Re: Minimum NTFS Permissions on the SystemDrive
- Next by thread: Re: Minimum NTFS Permissions on the SystemDrive
- Index(es):
Relevant Pages
|