Re: NT file system security



ykffc wrote:

If the following are requirements:

- these files cannot be accessed remotely by any person, including the administrators

It isn't possible to prevent a malicious administrator from accessing a file (or pretty much anything else). If is possible to prevent an administrator from accidentally accessing a file they aren't supposed to.

- For example, our Finance Mgr is the only person to access these files and we want him to be the only person having the key to those files.

If you really want the Finance Manager to be the only person who can access the files they will need to be on a stand-alone machine, preferably with no network connection, which he administers himself and which is physically secured. You also need to consider a backup system, and a recovery plan for the data if the Finance Manager is no longer available for whatever reason.

Harry.
.