Click here to get back home

Folder Security

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Folder Security Adrian 11-17-2006
---> Re: Folder Security Roger Abell [MV...11-18-2006
Posted by Adrian on November 17, 2006, 6:34 am
Please log in for more thread options
Hi Guys,

(Windows 2000 Domain, all servers 2000 standard.)

We have a folder called "Management" which contains a subfolder for each
department 5 in all. Each Deparment folder then is again divided into 7
further subfolders, each of which is again divided into further subfolders ..
anyway you get the picture.

This is the central file storage location and structure.

Twice over the last 3 months, these subfolders have been moved into
different departments subfolders essentially getting lost in the system and
have to be found and then moved back into position.

When I run ("cacls "R:\CENTRAL SERVICES " > c:\problem.txt) the output I get
is the following.

R:\CENTRAL SERVICES
NT AUTHORITY\Authenticated Users:(OI)(CI)(special access:
DELETE
READ_CONTROL
SYNCHRONIZE
FILE_GENERIC_READ

FILE_GENERIC_EXECUTE
FILE_READ_DATA
FILE_READ_EA
FILE_EXECUTE

FILE_READ_ATTRIBUTES

NT AUTHORITY\Authenticated Users:(OI)(CI)R
MyDomain\Domain Admins:(OI)(CI)F

Anyway I can Audit who or what is moving the folders? and is it possible to
lock these folders into place so they effectively cant be moved but the users
can still have full access to the subfolders?

Thanks

Posted by Roger Abell [MVP] on November 18, 2006, 12:50 am
Please log in for more thread options
Adrian,

You have a few questions here.

First, yes, you can audit. There are two steps. First, one the
storage machine in the Audit policy one must enable "Audit
object access". This step enables one to set auditing on and
for the specific things one wants audited. Next, one needs to
go to what should be audited (or a higher level in the parental
path) and set auditing. For NTFS, this is accessed in the normal
NTFS permissions dialog by selecting Advanced view and then
clicking into the Audit tab. Do not ask for more than you want
as a lot of security event log records can be generated. In your
case you might consider settings Audit for successful delete of
folders (use edit to select This folder and subfolders) by Everyone.

Next, you could use different NTFS permissions so that non-admin
accounts are not granted Delete for the folders that should not be
moved (by what you show they currently are granted that).

Now, if you determined that in
.\root
.\root\dept1
.\root\dept1\fixedA
.\root\dept1\fixedA\sub1
.\root\dept1\fixedA\sub2
etc
.\root\dept1\fixedB
etc
.\root\dept1\something1
.\root\dept1\something2
.\root\dept2
.\root\dept2\fixedA
etc

the folders dept1, dept1\fixedA,dept1\fixedB should
not be movable (deletable) but the other dept1 related
folders should be (are user generated), then one would
set the NTFS permissions on those non-movable folders
so that non-admins could not delete them (using the edit
capability within the advanced view to select "This folder
only" for a List grant, and using "Subfolders and files" for
their modify grant).

What you would discover after this is that some user will
come along and "move" one of these folders and the content
will get moved (they have the right to move much of the
content) but then their "move" will fail when it attempts to
move the "fixed" folder. The result is that there is a copy
whereever they "moved" to and the moved-from "fixed"
part is still there but empty of movable parts. If they can
read and delete things they can do this and there is not much
(short of one-on-one user enlightenment) you can do about it.

Roger
> Hi Guys,
>
> (Windows 2000 Domain, all servers 2000 standard.)
>
> We have a folder called "Management" which contains a subfolder for each
> department 5 in all. Each Deparment folder then is again divided into 7
> further subfolders, each of which is again divided into further subfolders
> ..
> anyway you get the picture.
>
> This is the central file storage location and structure.
>
> Twice over the last 3 months, these subfolders have been moved into
> different departments subfolders essentially getting lost in the system
> and
> have to be found and then moved back into position.
>
> When I run ("cacls "R:\CENTRAL SERVICES " > c:\problem.txt) the output I
> get
> is the following.
>
> R:\CENTRAL SERVICES
> NT AUTHORITY\Authenticated Users:(OI)(CI)(special access:
> DELETE
> READ_CONTROL
> SYNCHRONIZE
>
> FILE_GENERIC_READ
>
> FILE_GENERIC_EXECUTE
> FILE_READ_DATA
> FILE_READ_EA
> FILE_EXECUTE
>
> FILE_READ_ATTRIBUTES
>
> NT AUTHORITY\Authenticated Users:(OI)(CI)R
> MyDomain\Domain Admins:(OI)(CI)F
>
> Anyway I can Audit who or what is moving the folders? and is it possible
> to
> lock these folders into place so they effectively cant be moved but the
> users
> can still have full access to the subfolders?
>
> Thanks



Posted by Adrian on November 20, 2006, 5:03 am
Please log in for more thread options
Roger,

Thanks for such a detailed post, I have amended my policy as you mentioned
now its just a matter of waiting till it happens again before I strike! ;)

Appreciate the help



Similar ThreadsPosted
How to set this Folder security October 5, 2006, 8:25 pm
Folder redirection and security November 9, 2005, 10:45 am
Folder security question February 10, 2006, 11:58 am
Folder security problem April 6, 2006, 1:27 am
Security on Tasks Folder April 24, 2006, 11:23 am
Folder and Files Security October 3, 2006, 1:46 pm
Folder Security Issue November 1, 2007, 10:53 am
Strange folder security problem October 4, 2006, 3:45 pm
Sensitive Folder Security - Best Practice November 24, 2006, 9:50 am
Folder/Share security question January 7, 2008, 10:17 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap