Jump to content

Windows XP Security behavior


XP_2600

Recommended Posts

Guys i need help with Windows XP NTFS security settings, here it is the scenario:

any Windows XP machine have built in Administator which is a member of the administrators group by default, and i checked again that its not a member of any other groups, so i created a folder lets say in D:\mynewfolder

and i go to advanced and moved the inheritance option (figure number 1), and then i back to the Security tab window and i added the administator account which named to (admin) and i give it full permissions(figure number2), and i added users group and i give it deny permission(figure number3) .(again the admin account is not a member of the users group(figure number4)), now when i log with admin account and try to open the folder i get access denied permission(figure number5), again admin account is not a member of users account, and again it have full access permissions in the folder, anyone have a logical reason why i cant open it ?

1vk2.jpg

2oy9.jpg

*Its a Windows XP Professional, and its a stand alone system (not a member of domain).

Link to comment
Share on other sites


Because "Authenticated Users" is in Users, and an authenticated user is just that: You have a valid account regardless of admin or other groups. This includes Administrator (or "admin" in your case). With NT, Deny takes precedence over Allow.

To fix your problem: simply remove "Users". If you don't want "Users" accessing the folder, you simply leave them out. Like an exclusive nightclub if you aren't on the list you aren't getting in.

Edited by redxii
Link to comment
Share on other sites

Yes I agree with the above comments, very well said.

Avoid setting Deny permissions if at all possible and keep everything as simple as possible.

I don't quite follow the rationale of only having Everyone (Allowed Full Control) in the Advanced Security settings.

Link to comment
Share on other sites

I've noticed a similar problem. I removed all existing permissions and then gave an account read permissions on the root of drive C. This is inherited for some folders, such as Program Files, but not others such as Documents and Settings. I even get this on other drives which don't contain system files. :blink: I have to manually add the account to that folder's permissions even though it should be inherited.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...