We have a pair of Dell Windows 2003 Servers (identical). The other day an experienced user discovered he could copy files to folders, copy files in folders, and delete them, in an area where he had no explicit permission to do other that read/execute.
I found a new group in the tree of folders (and on all folders throughout Both systems, which had special permission to "create files/write data" - "create folders/append data". The local group is "MySrvr\User". Properties of "User" contain the "MyDomain\Domain users" account. Obviously this allows anyone with an account to use the special permission on every folder in the system.
I have successfully removed the special permission from "MySrvr\User" on a few folders and, as expected,it prevented writing, copying, deleting.
What really concerns me is how the "MyDomain\Domain users" account got into the local User group, the User group got inserted into all folders and with special permissions.
The operating system was already installed when the machines were delivered. I have scoured the Microsoft site and can't find an explanation for this. I can continue to remove the special permissions - seems to work ok - but, AM I creating an unseen problem that will come back to bite?
Anyone have knowledge of/experience with this latest Microsoft "feature"?
Thanks,
Steve
I found a new group in the tree of folders (and on all folders throughout Both systems, which had special permission to "create files/write data" - "create folders/append data". The local group is "MySrvr\User". Properties of "User" contain the "MyDomain\Domain users" account. Obviously this allows anyone with an account to use the special permission on every folder in the system.
I have successfully removed the special permission from "MySrvr\User" on a few folders and, as expected,it prevented writing, copying, deleting.
What really concerns me is how the "MyDomain\Domain users" account got into the local User group, the User group got inserted into all folders and with special permissions.
The operating system was already installed when the machines were delivered. I have scoured the Microsoft site and can't find an explanation for this. I can continue to remove the special permissions - seems to work ok - but, AM I creating an unseen problem that will come back to bite?
Anyone have knowledge of/experience with this latest Microsoft "feature"?
Thanks,
Steve