Re: group vs individual user security

From: Joan Wild (jwild_at_nospamtyenet.com)
Date: 05/22/04


Date: Sat, 22 May 2004 10:21:39 -0400

TC wrote:
> "Joan Wild" <jwild@nospamtyenet.com> wrote in message
> news:<OhoLQZzPEHA.1312@TK2MSFTNGP12.phx.gbl>...
>> TC wrote:
>>
>> But you must do so.
>
> Why? (seriously)
>
> If you create a user & grant him permissions, I don't see why he
> couldn't use the things that you had granted him permission to use;
> even if he was not a member of any groups. (Haven't explicitly tested
> this, but!)

In order to work with the systems tables, all users must be a member of the
Users Group

-- 
Joan Wild
Microsoft Access MVP


Relevant Pages

  • Re: assigning DB-user to server role
    ... You should be able to grant object permissions to the roles only. ... If a user is a member ... EXEC sp_addrole 'MyRole' ...
    (microsoft.public.sqlserver.security)
  • Re: Granting permissions in ADAM
    ... role (or users group that you may have created) to the ADAM Readers role. ... To allow the user to update their own information you can grant NT ... permissions for the SELF principal on the child object attributes. ...
    (microsoft.public.windows.server.active_directory)
  • ASP 0177:800401F3 error on COM object instance creation
    ... That works perfect if IUSR_is a member of Administrators group, ... Users group has Modify ... permissions over Web Project directory ... registry permissions. ...
    (microsoft.public.inetserver.iis.security)
  • Re: MS Access 97 Security questions
    ... It sounds like the developer secured it so that the Users Group has some ... limited permissions ... user that is a member of the Admins Group, allows you to make the changes. ... The users in this case don't need to use the secure mdw. ...
    (microsoft.public.access.security)
  • Re: Administrators are treated as Users for file permissions
    ... Then if it does have a grant it must directly or indirectly ... >>just remove all grants made to the Users group. ... >>member of the Users group one must remove both INTERACTIVE ... No problem Qui-Gon Jinn ...
    (microsoft.public.windowsxp.security_admin)