Click here to get back home

Using CREATOR GROUP for files/folder

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Using CREATOR GROUP for files/folder Vince C. 07-11-2005
Posted by Vince C. on July 11, 2005, 10:43 am
Please log in for more thread options
Hi.

We have created user accounts (Active Directory) on our W2K server. It is
the main domain controller. Currently the primary group for all users is
"Domain Users". I'd like to add "CREATOR GROUP" to a group of files on the
disk. If I understood correctly that special ID refers to the primary
group of a user.

If I change the primary group to something else for a user in Active
Directory, will security attributes on files and folders change
accordingly or will the group still be the group the user belonged to when
he/she created the file?

For instance (in sequence):
1. change user "Frank" primary group (make sure user is not currently
logged on) from "Domain Users" to "Accounting" 2. add "CREATOR GROUP" to
security.

Will Frank's files now belong to "Accounting" or "Domain Users"?

Thanks in advance,
Vince C.


Posted by Steven L Umbach on July 11, 2005, 11:36 am
Please log in for more thread options
The primary group is used only by the posix subsystem which would not be
used in most domains.

Creator/owner is a holder. If creator/owner has permissions to a file/folder
then the owner of the file/folder will receive permissions that are assigned
to creator/owner rather that the normal permissions the user would receive
based on group membership. In other words if the domain users group has
read/list/execute/write permissions to a folder and creator/owner has full
control and a user creates/writes a new file to that folder and therefore
becomes the owner that user will have full control permissions to that
le. -- Steve



show/hide quoted text




Posted by Roger Abell on July 11, 2005, 10:36 pm
Please log in for more thread options
Actually Steve OP is asking about the Creator Group special principal,
not Creator Owner, and OP is correct, this is one of the two actual uses
of the primary group introduced with Whistler versions of OS that are
actually Windows (i.e. not Posix) usages.

--
Roger Abell
Microsoft MVP (Windows Security)

show/hide quoted text
file/folder
show/hide quoted text
assigned
show/hide quoted text
is
show/hide quoted text
the
show/hide quoted text
when
show/hide quoted text




Posted by Roger Abell on July 11, 2005, 10:51 pm
Please log in for more thread options
show/hide quoted text

Oops, not sure why I said that, this use of primary group with the
Creator Group principal was introduced with Windows 2000
--
Roger
show/hide quoted text
receive
show/hide quoted text
full
show/hide quoted text
therefore
show/hide quoted text
is
show/hide quoted text
to
show/hide quoted text




Posted by Steven L Umbach on July 12, 2005, 2:42 am
Please log in for more thread options
OK. Thanks for correcting me on that. That will give me something new to
play around with too. --- Steve


show/hide quoted text




Similar ThreadsPosted
Permissions for all of group to read, only creator can modify October 3, 2007, 8:58 pm
Using CREATOR OWNER February 5, 2007, 2:38 am
What is the point to add special permissions for CREATOR/OWNER November 16, 2005, 4:07 pm
Why doesn't Group Policy work if I put a local group in the affected OU instead of the actual user account? January 27, 2009, 2:05 pm
Windows 2008 Standard : make a group a member of a group not possible ? September 25, 2009, 10:47 am
local group / global group permissions problem August 18, 2005, 12:42 pm
Can I delete 'Athenticated Users' group form local 'Users' group January 29, 2008, 11:52 am
ACL with group name starting with a # June 16, 2005, 9:57 am
Group Policy???? June 26, 2005, 11:39 am
Group Policy April 25, 2006, 11:58 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy