Re: deleting users my document folders after disabling redirection



Dave Nickason [SBS MVP] wrote:
There used to be a question on the old NT FAQ site: I set the
permissions for the "everyone" group to "deny" and now no one can
access the files.
That's still my favorite tech question of all time : -)

Kinda like the modern day 'logon locally, or deny logon localy", eh.

Fortunately all the 'trump' cards are still held by the administrators.




"kj [SBS MVP]" <KevinJ.SBS@xxxxxxxxxxxxxxxxxx> wrote in message
news:O0QXKkfMIHA.1168@xxxxxxxxxxxxxxxxxxxxxxx
Dave Nickason [SBS MVP] wrote:
Yes, but once you're the owner, you can remove the deny, right?

Yes, most likely. I suppose it would depend upon what the deny was
(take ownership, change permissions...) and whether it was just the
admin or the group.

Worth a little lab trial.



"kj [SBS MVP]" <KevinJ.SBS@xxxxxxxxxxxxxxxxxx> wrote in message
news:%235RaDieMIHA.4476@xxxxxxxxxxxxxxxxxxxxxxx
Dave Nickason [SBS MVP] wrote:
I would speculate that this would just make it a little harder for
admins to browse peoples' private folders. It's also possible
that changing ownership is a right that could be taken away from
certain admins to completely prevent them from viewing those
files - not sure about that one.

I've not tried it, but if a deny 'administrator' or
'domain\administrators' was placed on the directory\files, then
ownership should have not been helpfull as the deny would override
ownership. Interesting. bad idea, but interesting.



"Dan Shallbetter" <DanShallbetter@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote
in message
news:2FCE07B5-B7D9-49D1-A051-F774DCC1D352@xxxxxxxxxxxxxxxx
Dave,

Logging in as administrator and following your directions I still
received access denied. I added everyone with full permissions
and was able to finish
the task. Why would my system admin account be restricted?

Thanks,

Dan


"Dave Nickason [SBS MVP]" wrote:

Open the properties of the folder and go to the Security tab.
Click Advanced and go to the Owner tab. Replace the current
owner (the ex-user)
with Administrator or another domain admin account, checking the
box to apply the change to subfolders etc. Apply the change,
and you'll be able to
delete the folder (and change security permissions, or whatever
else you wish).


"Dan Shallbetter" <DanShallbetter@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote in message
news:A11424D9-5127-471F-A1F1-37E7AC0024FF@xxxxxxxxxxxxxxxx
How do I deleted users my document folders from the server.
Logging in as
server administrator I get access denied. SBS 2003 premium SP2

Thanks,

Dan

--
/kj

--
/kj

--
/kj


.



Relevant Pages

  • Re: Permissions question
    ... No need to create a new Administrators group. ... there you will see the option to deny "Take Ownership". ... We have a turnover of contractors that use the admin login ...
    (microsoft.public.windows.server.sbs)
  • Re: deleting users my document folders after disabling redirection
    ... There used to be a question on the old NT FAQ site: I set the permissions ... changing ownership is a right that could be taken away from certain ... Logging in as administrator and following your directions I still ... Why would my system admin account be restricted? ...
    (microsoft.public.windows.server.sbs)
  • RE: File and email Security
    ... Subject: File and email Security ... Oddly enough, every time I "take ownership" of files as an administrator, it ... only way an admin can access them is to seize ownership themselves, ...
    (Focus-Microsoft)
  • Re: deleting users my document folders after disabling redirection
    ... I suppose it would depend upon what the deny was (take ... changing ownership is a right that could be taken away from certain ... Logging in as administrator and following your directions I still ... Why would my system admin account be restricted? ...
    (microsoft.public.windows.server.sbs)
  • Re: Administrator Locked out
    ... an admin, remove the Deny and promptly use gpedit to revert the ... Simplify Group Policy Troubleshooting with the NEW GPExpert ... out the administrator from entering into the Group Policy Object ...
    (microsoft.public.windows.group_policy)