Click here to get back home

ACLs - Users with READ can MOVE a whole folder?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
ACLs - Users with READ can MOVE a whole folder? Gerry Hickman 04-11-2007
Posted by Gerry Hickman on April 11, 2007, 10:45 am
Please log in for more thread options
Hi,

I have a mapped drive as follows

U:\ (users full)
Shared Docs (users full)
Computer Docs (users Read and Execute)
Other Docs (users full)

In general it works as expected, ordinary users can't put docs into the
"Computer Docs" folder, nor delete them. If they try to move a sub-folder of
"Computer Docs" they get "Access Denied", BUT

If they drag and drop the WHOLE of "Computer Docs" into "Shared Docs", it
lets them do it! No questions! I don't understand this because even though
they're allowed to COPY the whole folder, I don't see how they can delete it
after. It's as if MOVE by dragging and dropping is not seen as requiring a
DELETE operation to complete??

Thanks for any help. This test was done with Win2k clients and servers, not
sure if the o/s makes any difference.

--
Gerry Hickman - (London UK)



Posted by Roger Abell [MVP] on April 12, 2007, 1:17 am
Please log in for more thread options
You are probably seeing an effect from the so-called "hidden child delete"
that is part of a full control grant as is a requirement for Posix
compliance.
Consider providing the Users group with Modify on U: or Modify and also
Change Permissions and Take Ownership if you do really want them to
have that. IIRC there is a discussion in the resource kit on the child
delete
included in full control.

> Hi,
>
> I have a mapped drive as follows
>
> U:\ (users full)
> Shared Docs (users full)
> Computer Docs (users Read and Execute)
> Other Docs (users full)
>
> In general it works as expected, ordinary users can't put docs into the
> "Computer Docs" folder, nor delete them. If they try to move a sub-folder
> of
> "Computer Docs" they get "Access Denied", BUT
>
> If they drag and drop the WHOLE of "Computer Docs" into "Shared Docs", it
> lets them do it! No questions! I don't understand this because even though
> they're allowed to COPY the whole folder, I don't see how they can delete
> it
> after. It's as if MOVE by dragging and dropping is not seen as requiring a
> DELETE operation to complete??
>
> Thanks for any help. This test was done with Win2k clients and servers,
> not
> sure if the o/s makes any difference.
>
> --
> Gerry Hickman - (London UK)
>
>



Posted by Gerry Hickman on April 12, 2007, 4:55 am
Please log in for more thread options
Hi Roger,

Yes, it looks like the problem is related to users having full control
instead of modify only. In general, all our shares are set up for modify
only, but this one was left over from years ago and I never got round to
changing it!

Thanks for solving it.

--
Gerry Hickman - (London UK)

> You are probably seeing an effect from the so-called "hidden child delete"
> that is part of a full control grant as is a requirement for Posix
> compliance.
> Consider providing the Users group with Modify on U: or Modify and also
> Change Permissions and Take Ownership if you do really want them to
> have that. IIRC there is a discussion in the resource kit on the child
> delete
> included in full control.
>
> > Hi,
> >
> > I have a mapped drive as follows
> >
> > U:\ (users full)
> > Shared Docs (users full)
> > Computer Docs (users Read and Execute)
> > Other Docs (users full)
> >
> > In general it works as expected, ordinary users can't put docs into the
> > "Computer Docs" folder, nor delete them. If they try to move a
sub-folder
> > of
> > "Computer Docs" they get "Access Denied", BUT
> >
> > If they drag and drop the WHOLE of "Computer Docs" into "Shared Docs",
it
> > lets them do it! No questions! I don't understand this because even
though
> > they're allowed to COPY the whole folder, I don't see how they can
delete
> > it
> > after. It's as if MOVE by dragging and dropping is not seen as requiring
a
> > DELETE operation to complete??
> >
> > Thanks for any help. This test was done with Win2k clients and servers,
> > not
> > sure if the o/s makes any difference.
> >
> > --
> > Gerry Hickman - (London UK)
> >
> >
>
>



Similar ThreadsPosted
Event ID for Move Users December 28, 2007, 1:51 am
Why Are List Folder / Read Data Combined? November 21, 2005, 10:45 pm
Copy all ACLs from one folder to copy February 21, 2008, 2:46 am
users, groups, and access to a folder May 2, 2006, 11:17 pm
Why my users can't change their home folder permissions while they ... August 28, 2006, 5:05 am
Compare ACLs April 29, 2008, 5:10 pm
Junction Points and ACLs September 20, 2005, 9:02 am
Removing System SID from ACLs August 8, 2006, 2:40 pm
mandatory filesystem ACLs March 9, 2007, 4:14 pm
Moving ACLs to new server May 24, 2007, 12:08 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap