synaesthesia Posted May 3, 2016 Posted May 3, 2016 My mind has gone blank so this is probably simpler than my brain makes out. It was brought to my attention today that staff users appear to have access to folders they shouldn't, such as a folder called "CONFIDENTIAL". The permissions all appear correct, so only the 5 specified users and Administrators group can access it. However, anyone that can access the shared drive it's on can access it. Removing "Administrators" removes their rights, yet I can't find anything to suggest said user(s) are in any way in the Administrators group. I can't find any groups that are linked to it (have checked members of Administrators), the accounts are local administrators but local admin is not linked to domain admin anywhere I can see. Have created a fresh user account and have verified this occurs with no other groups added anyway. Even if I do an Effective Access Check for my test user on the folder, it's allowed all the way through. It therefore appears as if everyone is in the Administrators group, despite lack of evidence to support that. Where on earth can I start to look?
Steve21 Posted May 3, 2016 Posted May 3, 2016 Is it deffo the admin group that's causing it? Found a lot of our old servers before I joined had "local users" left on it so always could access it. Was it local admin group or network admins when you say administrator group? Steve
Willott Posted May 3, 2016 Posted May 3, 2016 Is the server the file share on a DC, and if not, have staff somehow been added to the local administrators group on that server (check in compmgmt.msc)
synaesthesia Posted May 3, 2016 Author Posted May 3, 2016 Have checked all that, local groups & users on server and laptops, nada It is a file share on a DC. I'm almost certain its something related to the Administrators group as when I remove Administrators access from a folder, access from the normal users is stopped.
synaesthesia Posted May 3, 2016 Author Posted May 3, 2016 Gack, scratch that. Some plum (thankfully not me!) had decided to add all VPN users as domain admins. Slow clap. 2
Michael Posted May 3, 2016 Posted May 3, 2016 I've seen similar bad practice before - local admins has no bearing, but you're right, somewhere in AD you'll start to see links, linking back to Domain Admins, making permissions worthless. Unfortunately there are IT companies that employ Techs that don't understand permissions... best advice is look at what groups the select users are members of and narrow it down that way.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now