Re: File Share security permission



If the permissions are for domain admins and you are using a local admin
account that is not a memeber of the domain admins group then something else
is happening..

Do you have the same password for local administrator and for domain
administrator?

There is also ownership rights of file and directories so if all access
rights are removed then the owner can amend.


"Andy Wolsten" <AndyWolsten@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:577251C2-9BD9-4B9F-A3C8-DFB47BADFC1E@xxxxxxxxxxxxxxxx
Hi,

Could anyone advise on general good practice security permissions to set
for
general file shares.

Our system typically has the following settings:

- At the share level, 'everyone' has change permissions
- At the security level, specific settings applied to domain security
groups

I have just noticed that when logged in locally to a pc as local admin,
which is joined to the domain, I can create and delete files and folders
despite the folder security being set to domain users read, domain admins
full control?

am i doing something wrong?




.



Relevant Pages

  • Re: Users cannot run local appliactions .. pls help!!...
    ... that software may need local admin on that domain ... account or try logging in as admin and reghack the permissions on the ... >> better security from vendors and hold them responsible. ... "Don't lose sight of security. ...
    (microsoft.public.win2000.security)
  • Re: Domain groups show up as a SID
    ... I believe that is the way security ... If you logon as a member of a Domain Admins group, but the Local Admins group is ... So if the Domain Admin group has an account named Administrator and the Local ... SID's for all Permissions viewed and granted to any Domain Account. ...
    (microsoft.public.win2000.security)
  • Re: BIG Security Problem?
    ... The login is DEFINATLY not getting local admin ... >before attempting to test what the domain admins could ... >permissions aren't removed until that happens. ...
    (microsoft.public.win2000.security)
  • RE: Active Directory network security
    ... >Subject: RE: Active Directory network security ... >X-Mailer: Microsoft Outlook, Build 10.0.2627 ... In fact the only true security boundary in AD is a forest. ... >Domain Admins must be fully trusted. ...
    (Focus-Microsoft)
  • Re: Grant Administrative Access to a Domain Controller
    ... Create an account and allow them full ... Remember that objects ALSO have explicit defined permissions. ... you did not mention the domain administrators group (not Domain Admins). ... Objects protected by the AdminSDHolder only have explicit defined permissions which are the same as the AdminSDHolder object itself. ...
    (microsoft.public.windows.server.active_directory)