Re: Bug in 2008 security?
- From: "JackH" <grandam010nospam@xxxxxxxxx>
- Date: Tue, 3 Nov 2009 19:27:35 -0500
Here they are:
Anyone in the Termed Staff security group should have read only permissions
to the following location. Folders within this, permissions are granted on
a per user basis. Folders within this location have the same security
listed below except the termed Staff security group is removed.
d:\dfsroots\Termed Staff
Administrators full control
Creator Owner special
Domain Admins full
System full
Termed Staff Read & Execute, list, read
Permissions are the same as above via the dfs.
I think I see what the issue may be. I've found that is
domain\administrators have access then all domain users have full control.
I have no idea why this is as domain users are not in the administrators
group.
"neo" <neo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:%23jFn7tHXKHA.1236@xxxxxxxxxxxxxxxxxxxxxxx
Please post/review the share and ntfs permission on both dfs path and the
location it points to. One of them has something you don't expect.
"JackH" <grandam010nospam@xxxxxxxxx> wrote in message
news:eXyMzIBXKHA.4688@xxxxxxxxxxxxxxxxxxxxxxx
That's what I was referring to was the NTFS permissions.
"neo" <neo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:%235ltt$AXKHA.3720@xxxxxxxxxxxxxxxxxxxxxxx
Not knowing exactly what you need from this share, my gut says....
On share permissions tab, no. On NTFS permissions tab, yes.
"JackH" <grandam010nospam@xxxxxxxxx> wrote in message
news:OwiNNw9WKHA.3876@xxxxxxxxxxxxxxxxxxxxxxx
I believe because it is a DFS share? Is this not needed?
"neo" <neo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eT2Yvi7WKHA.1236@xxxxxxxxxxxxxxxxxxxxxxx
First question I would ask is why is your site going with "SYSTEM" on
the share permissions tab?
"JackH" <grandam010nospam@xxxxxxxxx> wrote in message
news:ucBYzL1WKHA.1232@xxxxxxxxxxxxxxxxxxxxxxx
I have several shares with permissions of Domain admins full control
and System special.
When staff try to access these folders they receive and access
denied. Which is great. However, I've found that these staff can
right click->properties->security tab and add them selves with full
control. How is this possible?
.
- References:
- Bug in 2008 security?
- From: JackH
- Re: Bug in 2008 security?
- From: neo
- Re: Bug in 2008 security?
- From: JackH
- Re: Bug in 2008 security?
- From: neo
- Re: Bug in 2008 security?
- From: JackH
- Re: Bug in 2008 security?
- From: neo
- Bug in 2008 security?
- Prev by Date: Re: Lost Domain Admin Password
- Next by Date: Re: Bug in 2008 security?
- Previous by thread: Re: Bug in 2008 security?
- Next by thread: Re: Bug in 2008 security?
- Index(es):
Relevant Pages
|