Folder permissions and take ownership

Folder permissions and take ownership

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Folder permissions and take ownership =?Utf-8?B?R3VubmE=?= 07-14-2008
Posted by =?Utf-8?B?R3VubmE=?= on July 14, 2008, 8:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi, I have a need to put an Active Directory group into the Administrators
group on a number of machines for various reasons which cannot be stopped.
The problem is there is an application on these machines that I do no want
them to be able to access and the aaplication has no ability to request
crednetials etc. It's just a dumb application.

I considered using FOlder permissions to lock out the local administrator
group from the folder. This stopped them from running the application until
I when in as one of the users and simple took ownership of the folder and
gave myself access. Then I tried adding a deny take ownership of the folder
to the local admin group. Again it just allowed me to take ownership
assuming becuase local admins can do that regardless of the deny rule I just
created.

Can anyone suggest how to stop them taking ownsership and from being able to
run the application?

Posted by Shenan Stanley on July 14, 2008, 8:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Gunna wrote:
> I have a need to put an Active Directory group into the
> Administrators group on a number of machines for various reasons
> which cannot be stopped. The problem is there is an application on
> these machines that I do no want them to be able to access and the
> aaplication has no ability to request crednetials etc. It's just a
> dumb application.
>
> I considered using FOlder permissions to lock out the local
> administrator group from the folder. This stopped them from
> running the application until I when in as one of the users and
> simple took ownership of the folder and gave myself access. Then I
> tried adding a deny take ownership of the folder to the local admin
> group. Again it just allowed me to take ownership assuming becuase
> local admins can do that regardless of the deny rule I just created.
>
> Can anyone suggest how to stop them taking ownsership and from
> being able to run the application?

If someone is an administrator on a computer - other than encryption and
other password-based limitations - you are not going to 'stop' them from
doing just about anything they please.

In other words - "administrators" is the default name of the group for a
reason. They can administer everything on the computer as they see fit.

What is this unstoppable reason to make these users administrators?
Political I assume?

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by =?Utf-8?B?R3VubmE=?= on July 14, 2008, 11:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yeh i thought you might say that. Partly political partly just a US company
and US mentality that "we" must be in control of all things...



"Shenan Stanley" wrote:

> Gunna wrote:
> > I have a need to put an Active Directory group into the
> > Administrators group on a number of machines for various reasons
> > which cannot be stopped. The problem is there is an application on
> > these machines that I do no want them to be able to access and the
> > aaplication has no ability to request crednetials etc. It's just a
> > dumb application.
> >
> > I considered using FOlder permissions to lock out the local
> > administrator group from the folder. This stopped them from
> > running the application until I when in as one of the users and
> > simple took ownership of the folder and gave myself access. Then I
> > tried adding a deny take ownership of the folder to the local admin
> > group. Again it just allowed me to take ownership assuming becuase
> > local admins can do that regardless of the deny rule I just created.
> >
> > Can anyone suggest how to stop them taking ownsership and from
> > being able to run the application?
>
> If someone is an administrator on a computer - other than encryption and
> other password-based limitations - you are not going to 'stop' them from
> doing just about anything they please.
>
> In other words - "administrators" is the default name of the group for a
> reason. They can administer everything on the computer as they see fit.
>
> What is this unstoppable reason to make these users administrators?
> Political I assume?
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>
>
>

Posted by Malke on July 15, 2008, 7:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Gunna wrote:

> Yeh i thought you might say that. Partly political partly just a US
> company
> and US mentality that "we" must be in control of all things...

Interesting. I would have thought that was a human condition and not limited
to a national mindset. In any case, Shenan is correct. If you are going to
give your users administrative powers, then they can do anything they want.
End of story. Either find a way to do what you need that doesn't include
making your users administrators or live with the consequences. Document
your actions. CYA isn't limited to any particular country.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ


Similar ThreadsPosted
Checking Folder Ownership and Permissions in VBScript November 11, 2005, 2:50 pm
Folder Ownership October 10, 2005, 12:38 pm
Cannot take ownership of a folder January 31, 2006, 6:47 am
Folder permissions April 26, 2007, 9:28 am
Folder permissions October 25, 2007, 6:26 pm
Folder permissions November 5, 2007, 8:17 am
Permissions on created folder July 28, 2005, 12:37 pm
Remove all permissions from folder February 13, 2006, 5:25 am
Setting Folder Permissions????? March 17, 2006, 12:40 pm
Folder/File Permissions April 21, 2006, 10:05 am

The site map in XML format XML site map

Contact Us | Privacy Policy