AD Builtin Users Group odd NTFS permissions
Windows Server 2003 SP2 with current updates available installed. Actaing as 1 of 2 DC in a domain.Running as a virtual machine on ESXi managed by vCenter.When I create a new drive on the Windows server, the bultin group <domain>\Users is getting 2 special permissions that I don't understand. The first is CreateFolders/Append Data, not inherited, applies to This folder and subfolders. The second is Create Files/Write Data, not inherited, applies to subfolders only. Since Authenticated users and Domain Users are members of this builtin group, all authenticated users are inheriting these permissions throughout the entire file system and can pretty much do anything they want with files and folders in any folder on the drive. What's up with this? Any ideas?Thanksdon
December 2nd, 2009 1:03am

Hi,As far as I know, they are the default permission entries for a new drive. When you check the Security tab of the C drive, you should find that it has the same permission entries.Please let me know if I have misunderstood your concern.This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
December 4th, 2009 12:15pm

No, no, I understand, just kinda surprised and wanted to confirm that I was not seeing something unusual on my systems.thanks for the infodon
December 10th, 2009 4:40pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics