Re: User rights.

From: Rob (rpayne1@cogeco.ca)
Date: 05/22/02


From: "Rob" <rpayne1@cogeco.ca>
Date: Wed, 22 May 2002 08:12:02 -0700


> An account has for permissions and rights the sum of
> all permissions and rights granted to any and all groups
> of which the account is a member, minus all rights and
> permissions that are denied to it.

>From this I think I can infer that I am a member of both the administrator
group as well as the user group and as such denying delete rights to the
user group denies this right to me also ?

> I am an administrator and should have cart blanch on the system. I should
be able to delete files at will.
So no, carte blanch for Administrators is not included - but the door key,
of
> always being able to take ownership, is.

I understand there are some directories on the system that even I can't do
anything with. These would include system critical files and directories. I
also understand the need for this type of protection in most cases.

> In your situation you might consider defining a custom
> group, ControlledUsers or whatever you wish, and placing
> those accounts as members of it. Then, use this group to
> deny (i.e. override any grant of) write in areas, or to grant
> modify in others.

So therefore the assumption I made was correct in that I do need to create a
new group and include my Son and my Wife only in it. does this also mean
that I can't assign rights on a user level as I can in other multi user
systems that I will not mention here "Novell or UNIX.... oops". Can I assign
rights on a file level also ?

Keep in mind that modify includes delete.
> (renaming in a sense creates the new and deletes the old)
>
> For the directory control you mentioned for one area, the
> modify/delete contention is handled by granting write (but
> not modify) which enables creation, and also granting a
> modify to the Creator Owner built-in .
>

Thank you for the information Roger it would seem you are the only one
'Brave' enough to answer the questions I put forth I will do as you have
stated and play with it a bit. other systems I have used define modify as
something a bit different than what you stated. ie modify is more of an
append rather than a recreation of the file as you seem to have implied.

> --
> Roger Abell
> MVP (Windows Platform) Associate Expert
> The Expert Zone - www.microsoft.com/windowsxp/expertzone
>



Relevant Pages

  • Problems with user accounts/security settings
    ... I created a new user with the exact same rights as other users in her ... Some network shares she can write to, ... a member of a group that has 'Read, Read & Execute and List' rights. ... She's trying to modify office documents and they all open 'read-only' (she ...
    (microsoft.public.win2000.security)
  • Problems with user accounts/security settings
    ... I created a new user with the exact same rights as other users in her ... Some network shares she can write to, ... a member of a group that has 'Read, Read & Execute and List' rights. ... She's trying to modify office documents and they all open 'read-only' (she ...
    (microsoft.public.win2000.active_directory)
  • Re: DC v Heller: Amicus Brief of the Real Linguists, Part I
    ... Otherwise, a foreigner like Verdugo could, but Rehnquist rightly pointed out that as he was NOT a member of THE PEOPLE CLASS, he could NOT claim the right, even though he IS an individual, but NOT AN INDIVIDUAL MEMBER OF THE PEOPLE. ... But, as Rehnquist points out, the rights of the 4th Amen extend ONLY to THE PEOPLE! ... How would an 80-year-old black woman from Haiti having an "individual right" to "own and carry guns" further the security of a free state to have a well-regulated militia, when such a person would be FOUR WAYS prohibited from SERVING in the militia or VOTING for the legislature that organizes and controls it? ... OR, and this is where the BoR comes in, any rights they MAY have claimed were not PROTECTED or GUARANTEED by the Constitution! ...
    (talk.politics.guns)
  • Re: Senate Republican Leader Mitch McConnelL Nixes District Of Columbia Voting Rights In Sente
    ... House Member ... representation in the U.S. House. ... The bill would grant full voting rights to the District's ...
    (talk.politics.guns)
  • Re: Delegation of groups admin. - restricted to a subset of object
    ... goto the members tab and add something as a member ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... * This posting is provided "AS IS" with no warranties and confers no rights! ... OU's and if in my ou i have delegate only to computers to write memeberof ...
    (microsoft.public.windows.server.active_directory)