Click here to get back home

NTFS permissions/deny override bug?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
NTFS permissions/deny override bug? jsmall 11-01-2005
Get Chitika Premium
Posted by jsmall on November 1, 2005, 7:56 pm
Please log in for more thread options
Hi,

I have a Windows 2003 server, and Windows 2003 terminal server with the
following scenario.

I have a folder, with share permissions allowing full access to:

Domain\users

And I want to deny one specific user, so i setup a DENY entry.

I have found this did not work. The above "allow" is inherited, whereas
the DENY was not. The DENY should have overridden, but the user
continued to have access to the folder.

I have found however, changing the allow to :

Domain\Domain users

Does continue allowing access, however, correctly (as far as I
understand) DENY's the user in question access.

What am I doing wrong here, or is this a bug?



Posted by jsmall on November 1, 2005, 7:58 pm
Please log in for more thread options
Allow me to correct the above.
The share permissions are "full" to everyone.

I am using NTFS permissions.



Posted by Arek Iskra [MVP] on November 2, 2005, 8:26 pm
Please log in for more thread options
> Allow me to correct the above.
> The share permissions are "full" to everyone.
>
> I am using NTFS permissions.
>


Did you ask user to logoff/disconnect from the share after you made changes?

--
Arek Iskra
MVP for Windows Server - Software Distribution




Posted by jsmall on November 2, 2005, 9:50 pm
Please log in for more thread options
Yep. Rebooted the machine several times, though I don't think this
should matter.

I'm still replicating it on other servers successfully. Create a file
with these permissions:

Domain\Users ALLOW FULL
Domain\Bob DENY FULL

Logon as Bob. You will have full access to everything, despite DENY
supposed to being an override.


Arek Iskra [MVP] wrote:
> > Allow me to correct the above.
> > The share permissions are "full" to everyone.
> >
> > I am using NTFS permissions.
> >
>
>
> Did you ask user to logoff/disconnect from the share after you made changes?
>
> --
> Arek Iskra
> MVP for Windows Server - Software Distribution



Posted by Steven L Umbach on November 3, 2005, 12:43 am
Please log in for more thread options
Double check how the user is authenticating to that share/server. If
persistent alternate credentials are used for a mapped drive or stored
credentials for XP Pro the user may not be authenticating as himself. Next
time the user is connected to the share you can use Computer Managed/shared
folders-sessions to see what users are connected to the share and from what
computer. If that does not help use xcacls.vbs to enumerate permissions for
the folder and post results in a reply. Also check the users "effective"
permissions in the advanced page of security properties for the folder and
compare results to a server where you are not having the problem and make
sure the user in question is not owner of the folder.


http://support.microsoft.com/?id=825751 --- xcacls.vbs


> Yep. Rebooted the machine several times, though I don't think this
> should matter.
>
> I'm still replicating it on other servers successfully. Create a file
> with these permissions:
>
> Domain\Users ALLOW FULL
> Domain\Bob DENY FULL
>
> Logon as Bob. You will have full access to everything, despite DENY
> supposed to being an override.
>
>
> Arek Iskra [MVP] wrote:
>> > Allow me to correct the above.
>> > The share permissions are "full" to everyone.
>> >
>> > I am using NTFS permissions.
>> >
>>
>>
>> Did you ask user to logoff/disconnect from the share after you made
>> changes?
>>
>> --
>> Arek Iskra
>> MVP for Windows Server - Software Distribution
>




Similar ThreadsPosted
do allowed perrmisions override denyed permissions? April 29, 2007, 6:32 pm
NTFS Lockdown December 5, 2005, 1:37 pm
NTFS Permissions February 20, 2006, 7:11 pm
NTFS Permission April 21, 2006, 10:04 am
NTFS Permissions August 16, 2006, 4:44 am
NTFS Audit December 23, 2006, 11:32 pm
NTFS woes January 22, 2008, 8:14 pm
NTFS Permissions and subfolders December 14, 2005, 2:06 pm
NTFS , folder permissions ! Need Help January 4, 2006, 11:51 am
NTFS permission problem March 31, 2006, 11:36 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap