NTFS file/folder permission to a computer...

NTFS file/folder permission to a computer...

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
NTFS file/folder permission to a computer... Luca Fabbri 01-31-2007
Posted by =?Utf-8?B?THVjYSBGYWJicmk=?= on January 31, 2007, 10:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi.
Is it possible to assign security permission to a computer instead of to a
users or groups. I tried to put a computer name into file ACL and give it
"full permissions" but it doesn't work I get an error like this: "impossible
to access to a file in read-only mode".
I need to permit access to a file or folder for those users that only logon
to that computer.

Thank you a lot.

Bye, Luca

Posted by Roger Abell [MVP] on January 31, 2007, 11:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You can grant to a computer, but it will not do what you
are hoping. All accesses are checked against permissions
for the accessing account (not the computer the account is
logged into). A grant to a computer only allows access to
processes run by that machine's System account.

The message you cite is not what one would receive due
to a lack of permissions, which would run something like
"Access denied" instead of talk of read-only (at least if
the message is from the OS instead of from some installed
application.

Roger

> Hi.
> Is it possible to assign security permission to a computer instead of to a
> users or groups. I tried to put a computer name into file ACL and give it
> "full permissions" but it doesn't work I get an error like this:
> "impossible
> to access to a file in read-only mode".
> I need to permit access to a file or folder for those users that only
> logon
> to that computer.
>
> Thank you a lot.
>
> Bye, Luca



Posted by =?Utf-8?B?THVjYSBGYWJicmk=?= on February 1, 2007, 2:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Roger.
Thank you for answer.
So isn't there a way to permit access to a file or folder for all users that
only
logon from that computer ?

Thank you.
Bye, Luca

"Roger Abell [MVP]" wrote:

> You can grant to a computer, but it will not do what you
> are hoping. All accesses are checked against permissions
> for the accessing account (not the computer the account is
> logged into). A grant to a computer only allows access to
> processes run by that machine's System account.
>
> The message you cite is not what one would receive due
> to a lack of permissions, which would run something like
> "Access denied" instead of talk of read-only (at least if
> the message is from the OS instead of from some installed
> application.
>
> Roger
>
> > Hi.
> > Is it possible to assign security permission to a computer instead of to a
> > users or groups. I tried to put a computer name into file ACL and give it
> > "full permissions" but it doesn't work I get an error like this:
> > "impossible
> > to access to a file in read-only mode".
> > I need to permit access to a file or folder for those users that only
> > logon
> > to that computer.
> >
> > Thank you a lot.
> >
> > Bye, Luca
>
>
>

Posted by Roger Abell [MVP] on February 1, 2007, 3:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi Roger.
> Thank you for answer.
> So isn't there a way to permit access to a file or folder for all users
> that
> only
> logon from that computer ?
>

No, there is no good way.

One can, for example, allow Guest access and use the firewall or
IPsec to allow only that one computer to have access, but that is
about it. That of course makes the sharing-out machine pretty much
single purpose as far as its network visibility.


> "Roger Abell [MVP]" wrote:
>
>> You can grant to a computer, but it will not do what you
>> are hoping. All accesses are checked against permissions
>> for the accessing account (not the computer the account is
>> logged into). A grant to a computer only allows access to
>> processes run by that machine's System account.
>>
>> The message you cite is not what one would receive due
>> to a lack of permissions, which would run something like
>> "Access denied" instead of talk of read-only (at least if
>> the message is from the OS instead of from some installed
>> application.
>>
>> Roger
>>
>> > Hi.
>> > Is it possible to assign security permission to a computer instead of
>> > to a
>> > users or groups. I tried to put a computer name into file ACL and give
>> > it
>> > "full permissions" but it doesn't work I get an error like this:
>> > "impossible
>> > to access to a file in read-only mode".
>> > I need to permit access to a file or folder for those users that only
>> > logon
>> > to that computer.
>> >
>> > Thank you a lot.
>> >
>> > Bye, Luca
>>
>>
>>



Posted by on February 1, 2007, 9:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> I need to permit access to a file or folder for those users that only logon
> to that computer.

If both computers are in an native Active Directory domain, you can
accomplish this using custom Kerberos tickets. Basically, only the
computers with the tickets will be able to communicate. That secures
the computer layer. Then, set an ACL on CIFS and another on NTFS to
set security on the user layer.

J Wolfgang Goerlich


Similar ThreadsPosted
Specific user NTFS permission August 14, 2006, 7:43 am
NTFS permission change when migrating to new Domain September 29, 2008, 12:16 pm
User permission to open Open files in Computer Management May 16, 2008, 4:56 am
Do not have permission to view or edit permission settings for a folder June 17, 2005, 7:58 am
Computer Hacker is illegally creating a new logon on my computer November 10, 2007, 9:32 pm
User Permissions Differ from Computer to Computer October 24, 2005, 7:16 pm
Computer to Computer NtLmSsp authentication errors ? October 6, 2006, 5:25 pm
temporary permission July 12, 2005, 8:00 am
parental permission December 21, 2005, 7:58 pm
Help----Permission problems June 25, 2008, 8:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy