tighten security...question for Patrick Rouse

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Paul Young (anonymous_at_discussions.microsoft.com)
Date: 03/27/04


Date: Fri, 26 Mar 2004 20:01:15 -0800

Patrick,

I have seen several of your posts where you share with the
NewsGroup how to secure the Terminal Server with NTFS
permissions.

You have stated that you lock down the C:\ and the
C:\Program Files directories with Administrators, System
and Creator/Owner ( Full Control ) and Authenticated Users
( Read and Execute ). Assumption is that this is on a
Terminal Server running on a WIN2000 Member Server.

I have three questions for you:

A) on the C:\ - are these permissions for This folder and
files or for This folder, sub-folders and files?

B) I am sure that the Adminsitrators is the local
Administrators group. How about the Authenticated Users
and System? There is a Domain account ( mydomain\system )
as well as a local account ( termserv\system ). My guess
is that both are the local account.

C) on the C:\Program Files - these permissions would have
to be for This folder, sub-folder and files? I should
remove the default permissions and manually enter what you
have suggested.

Thank you,

Paul



Relevant Pages

  • Re: deny access to all but 1 folder
    ... The default permissions are what ... For the Borland and Developers folders, just set the NTFS ... MCSE, CCEA, Microsoft MVP - Terminal Server ... have access to one folder. ...
    (microsoft.public.windows.terminal_services)
  • RE: folder access on websrvr frm domain account
    ... folder which is inside of a folder that is used as IIS website folder to ... Share Permissions and NTFS Permissions are independent in the sense that ... nor on a terminal server accessed by several users. ...
    (microsoft.public.windows.server.networking)
  • Re: Computer componet of GP not being applied
    ... would expect that anything in the Computer Configuration portion of the GPO ... By "non-standard permissions", I mean what are the permissions on the GPO? ... If you look at the properties of the OU in which the Terminal Server resides ... > It all seems to be linked to the local user groups on the terminal server. ...
    (microsoft.public.windows.group_policy)
  • Re: Permission Issue? Icons Denied in Terminal Services
    ... That error message comes definitively from IEES. ... Have you added the fileserver to the local intranet sites? ... MCSE, CCEA, Microsoft MVP - Terminal Server ... may not have the appropriate permissions to access the item. ...
    (microsoft.public.windows.terminal_services)
  • Re: Folder & File Permissions
    ... Not sure I'm understanding you correctly - from the perspective of file permissions, users can only access the files they're supposed to have access to - their own files - right? ... I have SBS 2003 and a terminal server on Server 2003, ... If i have 2 users looking at the drop folder that is used by the program, ... permisisons for SYSTEM and administrators both set to full control. ...
    (microsoft.public.windows.server.sbs)