Re: Security Permissions Question
- From: "Herb Martin" <news@xxxxxxxxxxxxxx>
- Date: Fri, 12 Aug 2005 09:40:47 -0500
"Space Junk" <SpaceJunk@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8AF9C5E8-E29D-455A-AABA-D664800D4A03@xxxxxxxxxxxxxxxx
> I am trying to find out what is up with being able to add a "computer" to
an
> ACL. I have done this in testing with several objects, file, flder,
printer,
> but it does not seem to have any effect.
It does have an affect IF the computer were to access the resource.
Accessing resources by the computer itself seldom happens though.
> How can you restrict access to an object based on computer, rather than
user
> or group?
Just as you have done. BUT what you probably expected, e.g.,
restricting USER access due to the computer they used, will not
work.
The main place you will see the computer account used in such
restrictions is with Group Policy, especially Software package
installs from a GPO.
If you assign a package to a computer, that computer must be able
to access the "share" and the "NTFS files" in order to perform the
installation, even before any particular user logs onto the machine.
Also, the GPOs themselves can be given (or denied) permissions that
affect how the GPOs are applied to the computers to which they are
assigned.
Normally when a user accesses a file however, the user's account
is the only one checked for permissions.
--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]
.
- References:
- Security Permissions Question
- From: Space Junk
- Security Permissions Question
- Prev by Date: Cannot get to network in through Windows98 machines
- Next by Date: Restrict password policy for admins
- Previous by thread: Security Permissions Question
- Next by thread: Cannot give write permissions in a folder
- Index(es):
Relevant Pages
|