Click here to get back home

Using CREATOR OWNER

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Using CREATOR OWNER Will 02-05-2007
`--> Re: Using CREATOR OWNER Roger Abell [MV...02-05-2007
Posted by Will on February 5, 2007, 2:38 am
Please log in for more thread options
If you have a directory that several users will share (e.g., a public TEMP
directory), how can you configure security settings so that:

- any user can create a file and control reading/writing/deleting that file
- no user can read a file created by another user or by system

--
Will



Posted by Roger Abell [MVP] on February 5, 2007, 9:07 am
Please log in for more thread options
> If you have a directory that several users will share (e.g., a public TEMP
> directory), how can you configure security settings so that:
>
> 1 - any user can create a file and control reading/writing/deleting that
> file
> 2 - no user can read a file created by another user or by system
>

Depending on what your words mean in 1 this may or may not be
possible. The account that creates a file can control whether other
accounts (en mass or specifically one by one) can access the file,
but one cannot limit it to only controlling reading/writing/deleting
(it gets to control all of the permissions).

Take a fresh install of XP Pro.
As an admin create a new subfolder on the system's boot drive,
say, c:\test and then access the NTFS permissions dialog of c:\test.

You will see two grants to Adminstrators, one inherited and one
that is not inheritied (it resulted from the Creator Owner grant on
the parent c:\). Now, look at the two grants to the Users group,
both inherited from the parent. Remove the grant of Read and
Execute for This folder, subfolders and files that Users holds.

Now, log in as a non-admin and create something in c:\test.
Note that you would need to create it without navigating there
in Explorer as a non-admin no longer has privileges to do so.
(If by your 2 you only wanted to control access to the content of
the files, instead of removing the grant to Users of Read/Execute
one could replace it with a grant of List).

Roger



Similar ThreadsPosted
What is the point to add special permissions for CREATOR/OWNER November 16, 2005, 4:07 pm
Using CREATOR GROUP for files/folder July 11, 2005, 10:43 am
Permissions for all of group to read, only creator can modify October 3, 2007, 8:58 pm
Prevent logons other than PC owner? January 16, 2006, 5:32 pm
change file owner? April 4, 2006, 10:48 pm
Administrators do not have Owner Permissions August 16, 2006, 8:44 am
Removing Administrator as Owner on Profiles December 31, 2006, 4:13 pm
the file owner that created by a service September 6, 2007, 10:01 am
NTFS Drop Folder - Blocking Owner from changing files May 19, 2008, 4:26 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap