Security Template does not apply folder permissions

Security Template does not apply folder permissions

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Security Template does not apply folder permissions void.no.spam.com 01-02-2007
Posted by on January 2, 2007, 11:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Right now I have a folder that has some permissions directly on it. I
want to use a security template to modify it so that it does not have
any permissions directly on it and instead inherits permissions from
its parent.

I created a security template, and in the File System section I added
an entry for the folder. I checked the "Configure this file or folder
then" box, and then made sure there were no permissions in the Security
tab and that the Advanced section had the "Inherit from parent the
permission entries that apply to child objects" box checked.

Then I saved the template, went to Security Configuration and Analysis
and opened a database, imported the template, and then configured the
computer. But it didn't apply the template setting to the folder --
the folder still had permissions directly on it, and did not inherit
anything from its parent. I analyzed the computer, and in the File
System it did not have a green check mark or red X on the folder; it
just said "subitems defined".

As a side note, I did have an entry for a different folder in my
template (but that one was to directly define a permission onto the
folder). After configuring the computer, that setting was applied (it
showed the green check mark).

Anyone know why the security template doesn't work for a folder when I
want that folder to inherit permissions?


Posted by Roger Abell [MVP] on January 3, 2007, 3:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have never tried doing it that way, find it an interesting approach
(configure, but with no grants, however specifying to receive
inheritables), and am unsure just what did (or not) happen.
However, on an XP fully up-to-date, I cannot repro what you see,
instead seeing the expected behavior (i.e. dir is left with only
inherited permission settings). Does your line in the template
look like the following? (i.e. does it have 0,"D:AR" ?)
"%SystemDrive%\Temp\test",0,"D:AR"

As said, I have not done this objective that way, but instead define
permissions at the parent and specify to configure the parent and
replace existing permissions on substructure with inheritables.
Now, your circumstance might make that not workable, if the parent
has for example three subfolders and the one you want set to purely
inherit is only one (you want the other three unchanged). In that case
you would add definitions for the other two ticked for Do not allow
permissions to be changed. This would not work out so well if you
have a hundred subdirs, all but of few of which should be left as is.
However, that will do it.

Roger

> Right now I have a folder that has some permissions directly on it. I
> want to use a security template to modify it so that it does not have
> any permissions directly on it and instead inherits permissions from
> its parent.
>
> I created a security template, and in the File System section I added
> an entry for the folder. I checked the "Configure this file or folder
> then" box, and then made sure there were no permissions in the Security
> tab and that the Advanced section had the "Inherit from parent the
> permission entries that apply to child objects" box checked.
>
> Then I saved the template, went to Security Configuration and Analysis
> and opened a database, imported the template, and then configured the
> computer. But it didn't apply the template setting to the folder --
> the folder still had permissions directly on it, and did not inherit
> anything from its parent. I analyzed the computer, and in the File
> System it did not have a green check mark or red X on the folder; it
> just said "subitems defined".
>
> As a side note, I did have an entry for a different folder in my
> template (but that one was to directly define a permission onto the
> folder). After configuring the computer, that setting was applied (it
> showed the green check mark).
>
> Anyone know why the security template doesn't work for a folder when I
> want that folder to inherit permissions?
>



Posted by on January 3, 2007, 8:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Roger Abell [MVP] wrote:
> I have never tried doing it that way, find it an interesting approach
> (configure, but with no grants, however specifying to receive
> inheritables), and am unsure just what did (or not) happen.
> However, on an XP fully up-to-date, I cannot repro what you see,
> instead seeing the expected behavior (i.e. dir is left with only
> inherited permission settings). Does your line in the template
> look like the following? (i.e. does it have 0,"D:AR" ?)
> "%SystemDrive%\Temp\test",0,"D:AR"

I had originally encountered the problem on my XP laptop at home. Then
yesterday, I attempted to reproduce the problem on my XP machine at
work. But I couldn't reproduce it. However, I just did another test
on my work machine, and encountered the problem.

Here's what I did:

I created 4 directories:
- c:\testing\inherit_propagate (this was set to inherit perms from its
parent)
- c:\testing\inherit_replace (this was set to inherit perms from its
parent)
- c:\testing\noinherit_propagate (this had inheritance disabled, and
had some perms directly defined on it)
- c:\testing\noinherit_replace (this had inheritance disabled, and had
some perms directly defined on it)

(In addition, each of those directories contained 2 subdirectories for
the purpose of testing the Propagate and Replace options - one that
inherited, and one that did not inherit)

Then I created a security template and put 4 entries into the File
System section:
- one for c:\testing\inherit_propagate - I told it to disable
inheritance and directly define some perms, and then checked the
"Propagate" box
- one for c:\testing\inherit_replace - I told it to disable inheritance
and directly define some perms, and then checked the "Replace" box
- one for c:\testing\noinherit_propagate - I removed all directly
defined perms and checked the inheritance box, and then checked
"Propagate"
- one for c:\testing\noinherit_replace - I removed all directly defined
perms and checked the inheritance box, and then checked "Replace"

Then I saved the template, created a database, imported the template,
and configured the computer.

The c:\testing\inherit_propagate and c:\testing\inherit_replace
directories had the template applied properly. The
c:\testing\noinherit_propagate and c:\testing\noinherit_replace
directories were not affected at all.

I then analyzed the computer, and it reported the following:
- c:\testing\inherit_propagate - green check mark (however, it did not
put green check marks on the 2 subfolders for some reason)
- c:\testing\inherit_replace - green check mark, and also green check
marks on the 2 subfolders
- c:\testing\noinherit_propagate - nothing, and nothing on the 2
subfolders
- c:\testing\noinherit_replace - red X, but for some reason it put
green check marks on the 2 subfolders

Here is what the template looks like:

[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
Revision=1
[File Security]
"%SystemDrive%\testing\noinherit_replace",2,"D:AR"
"%SystemDrive%\testing\noinherit_propagate",0,"D:AR"
"%SystemDrive%\testing\delete_this_one",0,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
"%SystemDrive%\testing\inherit_replace",2,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
"%SystemDrive%\testing\inherit_propagate",0,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"


> As said, I have not done this objective that way, but instead define
> permissions at the parent and specify to configure the parent and
> replace existing permissions on substructure with inheritables.
> Now, your circumstance might make that not workable, if the parent
> has for example three subfolders and the one you want set to purely
> inherit is only one (you want the other three unchanged). In that case
> you would add definitions for the other two ticked for Do not allow
> permissions to be changed. This would not work out so well if you
> have a hundred subdirs, all but of few of which should be left as is.
> However, that will do it.

Hmm, let me think about that.

Thanks for your help, Roger.


Posted by Roger Abell [MVP] on January 4, 2007, 12:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
So I have to factor and group your test . . .

4 directories:

- c:\testing\inherit_propagate
(this was set to inherit perms from its parent)
template File System section:
I told it to disable inheritance
and directly define some perms,
and then checked the "Propagate" box
"%SystemDrive%\testing\inherit_propagate",0,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
> configure: had the template applied properly
> post-configure analyze reported:
green check mark, did not put green check marks on the 2 subfolders
comment:
that all seems normal; green check marks are placed where the
sddl requires a change, but it would result in no change.
the subfolders are not required to be changed (only if not aligned
to the spec)

- c:\testing\inherit_replace
(this was set to inherit perms from its parent)
template File System section:
I told it to disable inheritance
and directly define some perms,
and then checked the "Replace" box
"%SystemDrive%\testing\inherit_replace",2,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"

> configure: had the template applied properly
> post-configure analyze reported:
green check mark, and also green check marks on the 2 subfolders
comment:
as before, here subfolders were specified to be replace (2) regardless
Admittedly placement of checkmarks is a little "peculiar" and
takes some getting used to. Also, be aware the the counts of
discrepancies is known to be highly obscure (actually I was told
by a member of that team that it is actually just plain in error as
the summing propagates up)

- c:\testing\noinherit_propagate
(this had inheritance disabled,
and had some perms directly defined on it)
template File System section:
I removed all directly defined perms
and checked the inheritance box,
and then checked "Propagate"
"%SystemDrive%\testing\noinherit_propagate",0,"D:AR"
> configure: directories were not affected at all.
> post-configure analyze reported:
nothing, and nothing on the 2 subfolders
comment:
I do not repro this result
post-config analyze is green check, subdirs not checked
permissions are changed as expected, including the state
of the inheritance spec - but note, the non-inheriting subdir
is left unchanged (we are only propagating, not replacing
and that dir does not allow propagation onto it)

- c:\testing\noinherit_replace
(this had inheritance disabled,
and had some perms directly defined on it)
template File System section:
I removed all directly defined perms
and checked the inheritance box,
and then checked "Replace"
"%SystemDrive%\testing\noinherit_replace",2,"D:AR"
> configure: directories were not affected at all.
> post-configure analyze reported:
red X, but green check marks on the 2 subfolders
comment:
I do not repro this result
post-config analyze is green checked, subdirs green checked
permissions are as expected, including the state of the
inheritance spec, and entire sturcture is purely inheriting
from its parent, all subdirs included


Notes:
I defined the structure to parallel you cases, used your
template slightly editied, but in all critical ways unchanged,
did an NTbackup of the empty structure of dirs, opened
sec database in imported template with clearing, analyzed
(at this point variances were
red x at each upper dir, red x on each non-inheriting sub dir
of a *_replace upper dir, green check on each inheriting sub
dir of a *_replace upper dir, plain unmarked folders for all
sub dirs of *_propagate
these are what I would expect)
then configured, and finally reanalyzed.



> Roger Abell [MVP] wrote:
>> I have never tried doing it that way, find it an interesting approach
>> (configure, but with no grants, however specifying to receive
>> inheritables), and am unsure just what did (or not) happen.
>> However, on an XP fully up-to-date, I cannot repro what you see,
>> instead seeing the expected behavior (i.e. dir is left with only
>> inherited permission settings). Does your line in the template
>> look like the following? (i.e. does it have 0,"D:AR" ?)
>> "%SystemDrive%\Temp\test",0,"D:AR"
>
> I had originally encountered the problem on my XP laptop at home. Then
> yesterday, I attempted to reproduce the problem on my XP machine at
> work. But I couldn't reproduce it. However, I just did another test
> on my work machine, and encountered the problem.
>
> Here's what I did:
>
> I created 4 directories:
> - c:\testing\inherit_propagate (this was set to inherit perms from its
> parent)
> - c:\testing\inherit_replace (this was set to inherit perms from its
> parent)
> - c:\testing\noinherit_propagate (this had inheritance disabled, and
> had some perms directly defined on it)
> - c:\testing\noinherit_replace (this had inheritance disabled, and had
> some perms directly defined on it)
>
> (In addition, each of those directories contained 2 subdirectories for
> the purpose of testing the Propagate and Replace options - one that
> inherited, and one that did not inherit)
>
> Then I created a security template and put 4 entries into the File
> System section:
> - one for c:\testing\inherit_propagate - I told it to disable
> inheritance and directly define some perms, and then checked the
> "Propagate" box
> - one for c:\testing\inherit_replace - I told it to disable inheritance
> and directly define some perms, and then checked the "Replace" box
> - one for c:\testing\noinherit_propagate - I removed all directly
> defined perms and checked the inheritance box, and then checked
> "Propagate"
> - one for c:\testing\noinherit_replace - I removed all directly defined
> perms and checked the inheritance box, and then checked "Replace"
>
> Then I saved the template, created a database, imported the template,
> and configured the computer.
>
> The c:\testing\inherit_propagate and c:\testing\inherit_replace
> directories had the template applied properly. The
> c:\testing\noinherit_propagate and c:\testing\noinherit_replace
> directories were not affected at all.
>
> I then analyzed the computer, and it reported the following:
> - c:\testing\inherit_propagate - green check mark (however, it did not
> put green check marks on the 2 subfolders for some reason)
> - c:\testing\inherit_replace - green check mark, and also green check
> marks on the 2 subfolders
> - c:\testing\noinherit_propagate - nothing, and nothing on the 2
> subfolders
> - c:\testing\noinherit_replace - red X, but for some reason it put
> green check marks on the 2 subfolders
>
> Here is what the template looks like:
>
> [Unicode]
> Unicode=yes
> [Version]
> signature="$CHICAGO$"
> Revision=1
> [File Security]
> "%SystemDrive%\testing\noinherit_replace",2,"D:AR"
> "%SystemDrive%\testing\noinherit_propagate",0,"D:AR"
>
"%SystemDrive%\testing\delete_this_one",0,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
>
"%SystemDrive%\testing\inherit_replace",2,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
>
"%SystemDrive%\testing\inherit_propagate",0,"D:PAR(A;OICI;FA;;;BA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;BU)"
>
>
>> As said, I have not done this objective that way, but instead define
>> permissions at the parent and specify to configure the parent and
>> replace existing permissions on substructure with inheritables.
>> Now, your circumstance might make that not workable, if the parent
>> has for example three subfolders and the one you want set to purely
>> inherit is only one (you want the other three unchanged). In that case
>> you would add definitions for the other two ticked for Do not allow
>> permissions to be changed. This would not work out so well if you
>> have a hundred subdirs, all but of few of which should be left as is.
>> However, that will do it.
>
> Hmm, let me think about that.
>
> Thanks for your help, Roger.
>



Posted by Roger Abell [MVP] on January 4, 2007, 1:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
the form I used really should have been:


- c:\testing\inherit_propagate
(this was set to inherit perms from its parent)
template File System section:
I told it to disable inheritance (i.e. D:P)
and directly define some perms (i.e += D:PAR(...)(.))
template application: <--- <--- new <---
checked the "Propagate" box (sic - selected radio) (ie += 0,"D:P...)
"%SystemDrive%\testing\inherit_propagate",0,"D:PAR(...)(.)
etc.
instead of :
template File System section:
I told it to disable inheritance
and directly define some perms,
and then checked the "Propagate" box

Also . . .
I have hint to suspect issue is part in expectations of
just what Propagate means as distinct from Replace.
Prior does not, later does overrule an inheritance block.

--
ra



Similar ThreadsPosted
Folder Security/ Permissions problem on W2K3 March 1, 2006, 11:25 pm
Folder permissions April 26, 2007, 9:28 am
Folder permissions October 25, 2007, 6:26 pm
Folder permissions November 5, 2007, 8:17 am
Folder Permissions September 6, 2008, 2:54 pm
Permissions on created folder July 28, 2005, 12:37 pm
Remove all permissions from folder February 13, 2006, 5:25 am
Setting Folder Permissions????? March 17, 2006, 12:40 pm
Folder/File Permissions April 21, 2006, 10:05 am
special folder Permissions November 28, 2006, 4:34 pm

The site map in XML format XML site map

Contact Us | Privacy Policy