Windows 2003 Server C: drive permission issue

Hey all,

A few weeks ago I tried to install a new AV on my File Server (this is a Windows Server 2003 Standard server, SP2, attached to my EMC Clariion via an iSCSI connection. Outside of some EMC software and a few small apps, the C: drive is mostly clean). Anyway, the tech noticed it wouldn't install because the Everyone group wasn't at the root of C: as it is by default. In fact, when I looked at the Security Properites of the root of C:, only Admnistrators was listed. I know this isn't right unless it was changed by someone...all my other servers have Administrators, SYSTEM, Everyone, Users, etc. at the root.

Anyway, when I added Everyone and hit OK, it wiped out all my C: permissions for some reason (that is, the Security Properties of any folder or file on C: is blank). Using my other servers as a guide, I manually added the default C: permissions and majde sure they pushed to all subfolders and files (added Admnistrators, Everyone, SYSTEM, Users, and CREATOR OWNER).

This worked fine, and the server has has no issues since then. I tested all the apps, etc.

My question is...I haven't rebooted it yet, but have to soon to finish an install. Should it be OK since it's been fine since the change, or will a reboot potentially cause an issue I might not be seeing?

Thanks.
exadmin2006Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mcsweenSr. Network AdministratorCommented:
What you did may work fine but the default permissions are not the same in subfolders as they are at the root.  I would follow this to restore the default permissions before restarting, although, I do not think a restart will be a problem.

http://blogs.technet.com/askds/archive/2008/05/28/default-security-templates-in-windows-2008.aspx
0
exadmin2006Author Commented:
Thanks. I made sure the Windows and system32 folders were checked...those did have inheritance disabled and had the TERMINAL SERVER ISERS groups added, which I took care of. I also checked the permissions of the folders on where some of the apps and EMC stuff was installed.

Does that link have a connection? It looks like an article on default GPO templates.

Thanks!
0
leebaskinownerCommented:
I have done this same thing one time before. If you have tested the critical systems and they are still working after you have replicated the change to the subfolders you should be good to go. The rights should not change because of  a reboot. But services will be restarted.  

It is important for the System account to have full rights to the drive. In some cases the NetworkService is as important.

Before the reboot I would check Services.msc, make sure that your services have to appropriate rights to the necessary folders where the services reside.

For example, Open Serivces.msc , find the 'DHCP Client' service, open and click on the logon tab.

The account that is used to run this service must have rights to the service and or folder where the service resides. In this case windows\system32\ folder.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

mcsweenSr. Network AdministratorCommented:
0
exadmin2006Author Commented:
Thanks. Last question...if I run the command to reset the permissions, this will only affect the C: drive right? The server has a D; drive which is on the SAN, and this is where all the file server data lives (Finance, iT, Marketing, etc.). These have explicit, custom permissions. I want to make sure those won't reset.
0
mcsweenSr. Network AdministratorCommented:
This will reset just the C:\ drive permissions.

However I would make sure you run a full tape backup on the D:\ Drive before doing this "just in case"
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.