Re: Deny rights question

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 01/13/05


Date: Wed, 12 Jan 2005 23:03:50 -0700

That Administrator in the NTFS is likely the machine local
Administrator of the machine that is sharing out the storage.
The share level and NTFS level permissions must both
grant a permission (and neither deny it) to an account (even
if via a group) in order for it to be able to use that permission.

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCDBA,  MCSE W2k3+W2k+Nt4
"Jeff Cichocki" <jeffc@belgioioso.com> wrote in message 
news:%23BVDSPz9EHA.3504@TK2MSFTNGP12.phx.gbl...
> OK.  I have checked the shares and they are set to "Authenticated Users". 
> It must have been changed somewhere along the way.  When I check the 
> individual directories, there is the "Administrator" account assigned to 
> each directory with full control.  It looks like it is the domain admin 
> account to me.  Is it the share that is letting them have to much or is it 
> the "Administrator"?
>
> Thanks
>
> Jeff
>
>
> "Tyler" <Tyler@discussions.microsoft.com> wrote in message 
> news:ADFA86FA-1D17-4986-BC91-0EB48CCDF4AE@microsoft.com...
>> It sounds to me like the shares that they are browsing to are set wide 
>> open.
>> Either they have share permissions set to Everyone or Domain Users.
>>
>> When they are browsing through the network the folders that they can see 
>> on
>> any given server are network shares that they have permissions to.
>>
>> Tyler
>>
>>
>> "Miha Pihler [MVP]" wrote:
>>
>>> Hi Jeff,
>>>
>>> Being local administrator on local Windows XP computers doesn't give 
>>> users
>>> administrative permissions on any other computer in domain.
>>>
>>> If these users do have administrator permissions on domain server then
>>> something else must be miss configured.
>>>
>>> Can you check:
>>> * on domain (in e.g. your active directory) what groups are these users
>>> members of
>>> * permissions that are granted to the folders that these users can (but
>>> shouldn't) browse
>>>
>>> -- 
>>> Mike
>>> Microsoft MVP - Windows Security
>>>
>>> "Jeff Cichocki" <jeffc@belgioioso.com> wrote in message
>>> news:unxM%23hy9EHA.3236@TK2MSFTNGP15.phx.gbl...
>>> >I have a new 2003 environment that is managing some XP machines.  A few 
>>> >of
>>> >the XP machines have users that set up as local admins to their 
>>> >respective
>>> >machines.  Is there a way to prevent their local admin rights from 
>>> >giving
>>> >them admin rights to the domain servers?  Specifically, they can browse 
>>> >the
>>> >network and open any folder on the server because of this scenario.
>>> >
>>> > Thanks
>>> >
>>> > Jeff
>>> >
>>>
>>>
>>>
>
> 


Relevant Pages

  • Re: Windows 2003 DC Demotion / Promotion
    ... Windows Server 2003 SP1 introduces rights that give an administrator ... control over local and remote permissions for starting COM servers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Deny rights question
    ... Administrator of the machine that is sharing out the storage. ... Microsoft MVP (Windows Server System: ... >> Either they have share permissions set to Everyone or Domain Users. ... >>>>I have a new 2003 environment that is managing some XP machines. ...
    (microsoft.public.windows.server.security)
  • Re: Administrator not the Administrator ??
    ... Please post the ipconfig/all from the server. ... > I seem to be able to chage permissions in files and folders no problem. ... we had to re install the Snap in for GP as it ... >>>>> where, as the administrator, I though I had full control. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 5.5 -> 2003 upgrade problem
    ... And it is this domain administrator account that has service account admin ... How do I make the account I am logged onto the new server have admin ... but the error indicates that you have a permissions error. ...
    (microsoft.public.exchange.setup)
  • Re: Grey screen after login to 2003 TS
    ... Anything in the EventLog, especially the security log? ... I believe that this can happen when users have too few permissions on ... Run them as administrator (when no user ... MCSE,CCEA, Microsoft MVP - Terminal Server ...
    (microsoft.public.windows.terminal_services)

Quantcast