Solved

Members of Administrators Security Group do not inherit permissions of Group

Posted on 2010-08-25
4
890 Views
Last Modified: 2013-12-04
On a new Windows 2008 R2 Server, I have restricted access to a folder as follows:

Administrators - Full Control (This folder, subfolders and files only)
SYSTEM - Full Control (This folder, subfolders and files only)
CREATOR OWNER - Special (full control of subfolders and files only)

SYSTEM is the Owner

The Administrator user can browse the folder no problem, however, any other members of the Administrators group cannot browse the folder and receive Access Denied.

The other users have logged off and back in again and I have restarted the server.

The User is in the same OU as the Administrator user.

When I check effective permissions on the folder it shows that the users have full access.

Does anyone have any ideas?

Thanks

Will
0
Comment
Question by:TSC70
  • 2
  • 2
4 Comments
 
LVL 83

Expert Comment

by:oBdA
ID: 33520077
Welcome to User Account Control.
User Account Control Step-by-Step Guide
http://technet.microsoft.com/en-us/library/cc709691(WS.10).aspx

You can create another local (domain or local to the server) group "NTFS-Foldername-F" or whatever, then add the users or a global group containing these users (but NOT Admins/Domain Admins group!) to this group. This will allow you to use UAC while still having full access to the file system and without having to resort to a command line run as administrator (MS still doesn't offer a way to run Explorer with elevated permissions).
0
 

Author Comment

by:TSC70
ID: 33520216
Thanks oBdA

We had just managed to get explorer to run as admin by opening command prompt run as admin and then killing explorer and starting it from the command prompt - which solved the problem when I received your response.

Therefore, are you saying that it is necessary to add the new security group (or the users) to the folder?  I see that as a partial solution however, I have restricted many different folders and executables and this would be quite a lot of work to add the group to each location.

What I don't understand is that if the Domain Administrator user can log in and gain access to the folder, why when I copy its AD object and create a new user with the same memberships, does the new user not also have the same permissions?  Surely there must be a registry change to fix this...

Thanks

Will
0
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 33520409
Well, running Explorer "elevated" like this defeats the purpose of UAC, so you could just as well disable it.
It's not *necessary* to create a specific group with Full permissions for the drive/folder, but as I said, it allows you to use UAC and Explorer as before.
There are Explorer clones/replacements which you can run elevated without interfering with Explorer.
The reason why it works with the Domain Administrator is that UAC doesn't apply to the built-in administrator account. The "registry change to fix this" is obviously to disable UAC ...
0
 

Author Comment

by:TSC70
ID: 33521482
Thanks for all your help.

The solution we have used is two settings in GP:

Computer configuration-Policies-Windows Settings-Security Settings - Local Policies/Security Options:
User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode: Elevate without prompting
User Account Control: Run all administrators in Admin Approval Mode: Disabled

Restarted Server
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question