Very Specific NTFS Permissions

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Numpty (Numpty_at_discussions.microsoft.com)
Date: 01/18/05

  • Next message: Jerold Schulman: "Re: Change file date?"
    Date: Mon, 17 Jan 2005 20:19:08 -0800
    
    

    The permissions that are offered by NTFS are not granular enough for my needs.

    I have looked into the "Special Permissions" but there is no way that I can
    see to turn off List Folder Contents and still allow a script to access the
    files (as it knows the path to the file.)

    I looked into FTP as a possible solution but the technology was not built
    for this purpose and whilst it will hide the files, there is no way to
    execute the script properly from this location (and specify where the files
    actually are.)

    I want to edit the ACL at the lowest level possible, and DENY list folder
    contents, whilst still allowing read / execute. The traverse folder
    permission is supposed to do this to some extent but it does not work as
    expected.

    I am beginning to think that this is not possible with Windows, and am quite
    disappointed as I am trying to create a very simple solution and the
    limitation seems to be that if there was simply two check boxes instead of
    one, I could do exactly what I need to do.

    All ideas would be appreciated.

    -- 
    "Numpty"
    MCP - XP, 2000 Server & 2000 Active Directory
    

  • Next message: Jerold Schulman: "Re: Change file date?"

    Relevant Pages

    • Re: ACLs Security
      ... If you need to set more explicit permissions from ... the command line (than CACLS) you can use XCACLs, ... > List Folder Contain shows Read and Excecute in the Advanced Tab. ... > Now problem is how can i specify this in ACE String. ...
      (microsoft.public.win2000.security)
    • Re: File Replication errors n Event log on Server
      ... Authenicated users Read & Execute, List Folder Contents, read & special permissions special ... Server Operator - Read & Execute, List Folder Contents, read & special permissionsspecial permissions ...
      (microsoft.public.windows.server.general)
    • RE: Users must be Administrators to log on to terminal services?
      ... Administrators: Full Control ... Read & Execute, List Folder Contents, Read ... > The users should have read permissions on the documents and settings folder. ...
      (microsoft.public.windows.terminal_services)
    • RE: 404 Error - OWA - Certain User
      ... Click Services tab and select Hide All Microsoft Services and Disable ... Click User Template and Replace any previous permissions granted to the ... Authenticated Users - Read and execute, List folder contents, Read ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • Re: Scheduled Task Wizard hangs
      ... Try checking the permissions for 'c:\documents and settings\all users\start ... menu' and make sure that 'Everyone' and 'Users' have atleast 'Read Execute' ... , 'List Folder' and 'Read' ...
      (microsoft.public.windows.server.general)