Re: Domain Controller File Permissions on SYSVOL

Tech-Archive recommends: Speed Up your PC by fixing your registry



1) READ permissions against the SYSVOLs on other DCs
There are 2 SYSVOL (1 is shared).
What permissions are you talkinga about (NTFS or Share permissions).

IIRC: By default NTFS PERMISSIONS ARE: Administrators and System have full
control, Authenticated users and server operators have read permissions,
SHARE PERMISSIONS: Administrators Full control, everyone ahave read perm.
(Note: i'm talking about the Sysvol share folder)
--
I hope that the information above helps you.
Have a Nice day.

Jorge Silva
MCSE, MVP Directory Services
"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:EO-dndb-JZdBwmTbnZ2dnUVZ_rOpnZ2d@xxxxxxxxxxxxxxx
"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> wrote in message
news:OzsKX91$HHA.3716@xxxxxxxxxxxxxxxxxxxxxxx
Hi
DCs share the same permissions among all existing DCs.

That doesn't answer the original question. I'm asking do DCs need

1) READ permissions against the SYSVOLs on other DCs

2) MODIFY permissions against the SYSVOLs on other DCs

It's not a question about the sameness of permissions.

--
Will


"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:OrqdnTlH3LuqSWXbnZ2dnUVZ_qqgnZ2d@xxxxxxxxxxxxxxx
Do Domain Controllers only require read-only file system permissions to
the
SYSVOL on other Domain Controllers?

--
Will




.



Relevant Pages

  • Re: Help with GPO problem! PLEASE!!
    ... found by right clicking the sysvol share, ... authenticated users and everyone with read permissions and no deny ... >> sure that administrators and system have full control ntfs permissions to ... >>> Controller Security Policy or the GPO. ...
    (microsoft.public.windows.group_policy)
  • Re: Active Directory domain policy not available - Windows cannot access the registry information (5
    ... shuffling the registry around as a result. ... >What share permissions did you change? ... >SYSVOL and NETLOGON shares aren't accessible. ... >the domain controller is changed but the DNS still points to the old IP ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Active Directory domain policy not available - Windows cannot access the registry information (5
    ... What share permissions did you change? ... SYSVOL and NETLOGON shares aren't accessible. ... the error messages are generated. ... Printer Sharing service not being enabled on the Domain Controller ...
    (microsoft.public.backoffice.smallbiz2000)
  • RE: Sysvol and Netlogon Security Permissions
    ... You need to consider the effective permissions of the SYSVOL directory / ... When combining Share + NTFS permissions, ... only domain authenticated users will be granted read ...
    (microsoft.public.windows.server.active_directory)
  • RE: Folder redirection stopped working....
    ... In a share audit last week I noticed that the sysvol and netlogon folder ... how do I reset all my sysvol and netlogon permissions back to the "way ... Also, just in case, if I messed up the redirection folder as well, can ...
    (microsoft.public.windows.server.active_directory)