Re: Can It Be Done? - MDB Security

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 05/28/04


Date: Fri, 28 May 2004 18:43:22 GMT

On Thu, 27 May 2004 14:00:05 -0500, "Phillip Windell" <@.> wrote:

>Wouldn't you want to just remove Everyone from the list rather than
>explicitly "deny" them? Doing that would deny all users since all users are
>part of Everyone and this "explicit deny" would over-ride other permissions.

Everyone is a group, it's not "Every account on the system" so neither
removing Everyone from access or specifically denying Everyone will
actually stop every account from accessing the file.

But the real basis for the Deny is that a user may be a member of
another group that has explicit or inherited permissions to the
file/folder in question. With a Deny, everyone is denied access
explicitly. Which may again not be what is intended, since Everyone
is just a group anyway.

Better is to remove all access to the file/folder except for
administrators and the user in question. Watch for inherited rights
that may not be obvious. Put the users in a qroup that is allowed
access, then use the group account for access, that way changing
access is simply adding or removing users from the group.

Jeff



Relevant Pages

  • Re: Deleting ALL mail at once
    ... Removing an http accountdoes not impact the folders or messages residing on the Hotmail server ... Comparatively, if removing an http account in Outlook that was in use with the Outlook Connector, the user file associated with that accountis not removed from the Outlook message store location/hard drive. ...
    (microsoft.public.internet.mail)
  • Re: ISP Stumped
    ... this problem a while ago and I resolved it by removing a corrupt email ... > two of the account. ... > problem and the support does not support Outlook, ...
    (microsoft.public.outlook)
  • Re: TRUST RELATIONSHIPS
    ... Just like you have an account, ... Removing/joining a domain is done via the Network Identification button on ... make sure you know the W2k Pro's local administrator password before ... removing this from a domain, or else you may not be able to log into it ...
    (microsoft.public.win2000.security)
  • Re: People posting codes
    ... > If you're going to roll your own crypto at least do it right. ... Removing ... > formatting from the signatures/mac is just asking for trouble. ... The way I read his original post, he was trying to account for the fact that ...
    (sci.crypt)
  • Distribution Group Problem
    ... Help Desk was assigned a task of removing a user from 2 distribution groups ... The account was removed via ADUC. ... The user name in the error message is the name prior to it being changed. ... I have checked through the Deleted Objects container with LDP.exe and the ...
    (microsoft.public.exchange.admin)