Re: <Solved> Run-time version of Access bypasses Secured file

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Tony_VBACoder (anonymous_at_discussions.microsoft.com)
Date: 07/07/04


Date: Wed, 7 Jul 2004 10:56:16 -0700

Yup...there was a step that was omitted that related to
the Admin user getting all permissions. Once I reapplyed
User-Level Security and made sure to double-and-triple-
check all my steps along the way, everything is working
the way I expect it to.

Thanks for the all the help.

>-----Original Message-----
>"Tony_VBACoder" <anonymous@discussions.microsoft.com>
wrote in message
>news:281bf01c46420$be870fb0$a401280a@phx.gbl...
>> Paul, thank you for the reply, however, that is exactly
>> how I secured both my front-end and back-end database.
I
>> followed all 10 steps precisely, so I know that I
secured
>> it properly.
>
>You previously stated that when in the Runtime (without a
prompt) you see
>that the CurrentUser() returns "Admin". A properly
secured database should
>have zero permissions and zero ownership for the "Admin"
user so it would
>appear that your app is NOT properly secured.
>
>Have you double-checked whether "Admin" owns the database
and/or any
>objects within? This is easily missed and owners have
permissions above
>and beyond any that you have explicitly given them.
>
>
>--
>I don't check the Email account attached
>to this message. Send instead to...
>RBrandt at Hunter dot com
>
>
>.
>



Relevant Pages

  • Re: Security without signon
    ... So my situation continues to be that, using RWOP queries, I can achieve what the title of this thread refers to as 'security without signon' only if the owner of the RWOP query is given explicit permissions on the back-end tables rather than inherited permissions by virtue of group membership. ... It is the different experiences of the default Admin user in my scenario that might be the key to understanding what is going on here. ... There are two mdw files at play in my scenario: the one that I created to secure my database (SecureMDW), and the default one that comes with Access. ... SecureMDW contains these default accounts plus the account for my SuperUser and the account for my SuperGroup, and SuperUser is a member of SuperGroup. ...
    (microsoft.public.access.security)
  • Re: would it be wise???
    ... There are some permissions that are necessary by all users, ... The Admin user is only a member of the users group. ... If the user logs in with username and password from the correct ...
    (microsoft.public.access.security)
  • Re: Lost My Permissions
    ... you have reset the password for Admin user. ... which doesn't/shouldn't have any permissions. ... Accounts and click on change password and change the null password to ... our lowest level group that has read and modify data ...
    (microsoft.public.access.security)
  • Re: Security file not holding changes
    ... linked to the same back end mdb on the server. ... I thought all the security info was contained in the mdw file. ... >> first removed all the users except for myself and the admin user I created ... >> have permissions to the objects that their Group should have. ...
    (microsoft.public.access.security)
  • Re: Help -- My permissions are changing themselves!!
    ... I'm almost certain I have user-level security setup right. ... "Rick B" wrote: ... > the default SYSTEM.MDW and open the database, ... >> with permissions to modify these permissions (myself and one other ...
    (microsoft.public.access.security)