Re: XP Pro file permissions

From: Andrey Tarasevich (andreytarasevich_at_hotmail.com)
Date: 03/17/04


Date: Wed, 17 Mar 2004 13:41:13 -0800

Liam Falcon wrote:
> Since the administrator account in question is also a member of the Users group, the DENY ACL and any other ACLs will take place. DENY ACLs take precedence over Allow ACLs. So, this administrator has full control by the first ACL you created, but because of the DENY ACL for write for group "Users" also applies to Administrator, that account is denied writing. Thing to remember? DENY will overrule an allow. Use with caution.

Yes, that's the conclusion I came to. But where can I see some kind of
chart or diagram of whatever that shows, what users/user groups are
implicitly included into what other user groups? For example this case
demonstrates that all members of 'Administrators' group in XP are
treated as members of 'Users' group at the same time, even though on my
machine the 'Administrator' account is not included into 'Users' group
explicitly.

This also brings the next question: how do I explicitly deny some
inherited permission to 'Users' without denying it to 'Administrators'
on some folder 'F'? The only way I see now is to stop inheriting
permissions to folder 'F' and specify all permissions explicitly. Can it
be done without breaking the inheritance?

> Secondly, the Everyone group is called an implied group. It does not technically exist, but the system recognizes it as a collection of any and all people. With the creation of "Authenticated Users" we now have a greater ability to give more open ACLs without giving away access to unknown users.

Thank you for your reply.

-- 
Best regards,
Andrey Tarasevich


Relevant Pages

  • Re: Shared permissions vs. security
    ... If they need to write to that folder [which should not be the drive/root ... administrators group by default so you are giving redundant permissions. ... It is best practice not to logon as a domain admin to domain workstation ...
    (microsoft.public.win2000.security)
  • Re: Dont Administrators have access to everything?
    ... folder, which the Limited users getaccess to. ... One of the Administrators is the Owner of nearly every ... the few that can be opened, but I thought the Administrators ... If you're an admin and you take ownership, and you replace permissions, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Requesting general help with administartion
    ... you can use ntfs permissions to restrict users as to ... root/drive folder permissions so that users have only read/list/execute permissions. ... users can run/install and then exempt local administrators with the enforcement rule. ... I've just set up an XP Pro computer for a friend of mine, he's not so PC savvy and he ...
    (microsoft.public.windowsxp.security_admin)
  • Re: deny access to control panel for limited users
    ... files and system folder which regular users do not have in a default ... Use the command net localgroup administrators to see what ... See the link below on how to manage NTFS permissions if you are not ... easiest way to further lockdown other non administrator accounts in XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: XP Folder Ownership Problems, Permissions, Inheritances
    ... One of the reasons that messing with permissions is dangerous is that ... me a cacls output on the folder. ... > the owner Administrators, MS Word won't work when I log in as Kent. ...
    (microsoft.public.windowsxp.security_admin)