Solved

Via GPO add local group to ACL for a file

Posted on 2010-09-10
3
547 Views
Last Modified: 2012-06-21
On each domain member PC there is a local group called "specialUsers". They each have their own local SID as they were created with a locally run script. The group contains domain groups and domain users and local users.

We want to give that group permissions on a file local to that PC. For example, give it "deny full control" to "file1.txt" so that if you're a local user in that group or a domain user in the domain group which is a member of that local group, you cannot do anything to that file, even read it's contents.

Via GPO we have lots of file security permissions. We have common SID users and groups having or being denied access (like Administrators, Remote Desktop Users, SYSTEM, etc). If I back up the GPO and go to the GptTmpl.inf file I can see these ACL's listed under [File Security].

However I can't figure out how to create an entry that sets permissions to that local file on eac pc to the local group on that PC. I can't copy and paste one of the file entry lines and put in the SID of the local group because that SID doesn't exist on other PCs, only that one. I can't put just the display name instead of the SID (such as "Special Users" because when you try to restore that gpttmpl file or import it, it errors out.

Anyone have an idea on how to via group policy force each pc to add certain restrictions to a file for the same local group name even though the SIDs are different?

Thanks.
0
Comment
Question by:MrSampsonite
  • 2
3 Comments
 
LVL 31

Accepted Solution

by:
DrUltima earned 500 total points
Comment Utility
Would you be willing to use GPO to fire off a batch file?  If so, you could use the icacls command like to do this very easily:

icacls file1.txt  /deny specialUsers:F

Source for icacls, if you need it: http://technet.microsoft.com/en-us/library/cc753525%28WS.10%29.aspx
0
 

Author Comment

by:MrSampsonite
Comment Utility
It looks like your solution may be the only option. Thanks for the link.
0
 

Author Closing Comment

by:MrSampsonite
Comment Utility
only solution given was to create a batch file as it appears impossible via gpo.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

I'm sure that every Windows systems administrator has written, or at least used, a batch or VBS login script at some point in their career, whether it is to map network drives, install printers, or set some user preferences.  No more! With Window…
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now