NT AUTHORITY\Authenticated Users

Posted on 2013-11-11
Last Modified: 2013-11-11
Who exactly is NT AUTHORITY\Authenticated Users? I am trying to risk assess who can access a certain folder and this group appears, but I cant find it in AD, who is in it? Why would you need to add that group to a particular folder ACL? Will removing it break anything?
Question by:pma111
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 17

Expert Comment

by:Emmanuel Adebayo
ID: 39638670
Authenticated Users includes all users whose identities were authenticated when they logged on.


Author Comment

ID: 39638682
Sorry I dont really understand that - does it mean every user in the domain?
LVL 17

Expert Comment

by:Emmanuel Adebayo
ID: 39638691
Yes these are the users that are autehnticated by your Active directory.

Author Comment

ID: 39638724
So in a nutshell if one of your folders grants read access to NT AUTHORITY\Authenticated Users - then every user in the network can access it?
LVL 17

Accepted Solution

Emmanuel Adebayo earned 500 total points
ID: 39638858
Yes, you are right.

You allow this account permission to your folder only when you are convinced that you are willing to grant whatever permission was set to all who can successfully log on to the domain network because the permission will allow access to this account for everyone in the domain. If you find that you don't want to grant premission to everyone for that folder, i suggest  you remove it.


Featured Post

Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question