Re: Access denied

From: Doug Frisk (PublicNews_at_removeme.fazwak.com)
Date: 03/08/05


Date: Tue, 8 Mar 2005 15:18:01 -0600


<best@news.postalias> wrote in message
news:590901c52418$bab29d10$a601280a@phx.gbl...
> Hi All,
>
> How could a specific folder be configured with access
> denied even to administrators, except for the boss as the
> folder contains some confidential information ?
>
> Many thanks.

You cannot configure permissions to do this. Anyone who has administrator
level access to a machine can shoehorn into any file.

You *can* use EFS in this case. You would need to configure the encryption
recovery agent for those particular files to be a certificate that the
admins do not have access to. (They need to be stored on a floppy, CD or
USB pendrive or some other such thing.) If the certificates required to
decrypt the files are not available to the admins, they can see the files,
could even delete them, but not access them.

Now, the files can be on the network, the admins cannot decrypt them to view
them. This meets what I think you're trying to do, but be waned, if the
boss loses the exported certificates required to decrypt the files, you're
well and truly screwed.



Relevant Pages

  • Access denied
    ... How could a specific folder be configured with access ... denied even to administrators, except for the boss as the ... folder contains some confidential information? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Lack Sufficient Administrator Privileges
    ... Can you open Group Policy editor as in gpedit.msc and if so did you make the ... When you run the command net localgroup administrators ... root/drive folder, the program files folder, the \Windows folder, the ... > trying to install Quicktime, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lack Sufficient Administrator Privileges
    ... > Can you open Group Policy editor as in gpedit.msc and if so did you make the ... When you run the command net localgroup administrators ... > root/drive folder, the program files folder, the \Windows folder, the ... >> trying to install Quicktime, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Program Problems for non-administrators
    ... The user cant burn CDs because the media player absolutely wont function in her account but switch it to an administrator and all is well. ... User accounts will say they have an older version of a program but the administrators account says everything is up to speed. ... Quite simply, the installation routine for this application doesn't "know" how to handle individual user profiles, or the application tries to make changes to "off-limits" sections of the registry or protected Windows system folders. ... you can make this software available to other users by _copying_ the Start Menu folder and Desktop folder shortcuts from the user profile from which the software was installed in the corresponding folders in the user profilein which you'd like the software to be accessible. ...
    (microsoft.public.windowsxp.general)
  • Re: Home Folder Owner
    ... No...The Administrators is listed as Owner. ... ownership of the folder. ... But ownership by WSNTest should happen when the ...
    (microsoft.public.windows.server.active_directory)