Re: NTFS problem
- From: jsmall@xxxxxxxxxxxxxx
- Date: 15 Jun 2006 21:12:49 -0700
Hi Niv,
I'm not totally sure I follow the question.
Bob is mapping his H: to a share on a file server. Call it
\\server\data.
The Share level permissions on this share are "full control" for
everyone.
The file system level shares on the root folder as full control to
administrator, and read/write to domain users.
It's this account's folder where we disabled inheritance and locked
down. So far however, the lockdown doesn't appear to be 100%.
The permissions on the accounts folder are exactly as they are spelled
out below. Change permission to the Accounts group, Full Control to
administrator. No other permissions.
Niv Raz wrote:
Hi ,
Is user BOB maps to a knowen share? what is the permissions of this share?
what the permission of the folder (F/S Level)?
Cheers,
N.
<jsmall@xxxxxxxxxxxxxx> wrote in message
news:1150267154.732657.257800@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,
I posted about this a while back, but didn't get to follow it through.
Anyway, consider this command, where H: is mapped to a share on a
Windows 2003 file server:
H:\>cacls accounts
H:\Accounts Domain\Accountants:(OI)(CI)C
Domain\administrator:(OI)(CI)F
It demonstrates that the domain administrator has full control on the
"accounts" folder, and the accounts group has change control. No other
users should have access.
We have a user. Let's call him Bob. I have checked, double checked and
triple checked that he is not in the "accountants" group.
When he logs into a Windows 2003 terminal server, maps the drive in
question, he gets an "access denied" when he tries to open the folder
in question.
When he logs onto his Windows XP workstation, member of the same
domain, he CAN list the files in that folder. He cannot open them,
("access denied" again) but he CAN list them, which is a security issue
to us.
He does not have Full Control on the H:, and I have disabled caching on
the share as recommended already.
Any assistance appreciated.
.
- References:
- NTFS problem
- From: jsmall
- Re: NTFS problem
- From: Niv Raz
- NTFS problem
- Prev by Date: routing & remote access issues
- Next by Date: Re: Dynamic disks
- Previous by thread: Re: NTFS problem
- Next by thread: Re: Computer account in active directory
- Index(es):
Relevant Pages
|