Jump to content

Recommended Posts

Posted

My mind has gone blank so this is probably simpler than my brain makes out.

 

It was brought to my attention today that staff users appear to have access to folders they shouldn't, such as a folder called "CONFIDENTIAL". The permissions all appear correct, so only the 5 specified users and Administrators group can access it.

 

However, anyone that can access the shared drive it's on can access it. Removing "Administrators" removes their rights, yet I can't find anything to suggest said user(s) are in any way in the Administrators group. I can't find any groups that are linked to it (have checked members of Administrators), the accounts are local administrators but local admin is not linked to domain admin anywhere I can see.

Have created a fresh user account and have verified this occurs with no other groups added anyway.

Even if I do an Effective Access Check for my test user on the folder, it's allowed all the way through.

It therefore appears as if everyone is in the Administrators group, despite lack of evidence to support that.

 

Where on earth can I start to look?

Posted

Is it deffo the admin group that's causing it? Found a lot of our old servers before I joined had "local users" left on it so always could access it.

 

Was it local admin group or network admins when you say administrator group?

 

Steve

Posted
Is the server the file share on a DC, and if not, have staff somehow been added to the local administrators group on that server (check in compmgmt.msc)
Posted

Have checked all that, local groups & users on server and laptops, nada :( It is a file share on a DC.

I'm almost certain its something related to the Administrators group as when I remove Administrators access from a folder, access from the normal users is stopped.

Posted

I've seen similar bad practice before - local admins has no bearing, but you're right, somewhere in AD you'll start to see links, linking back to Domain Admins, making permissions worthless.

 

Unfortunately there are IT companies that employ Techs that don't understand permissions... best advice is look at what groups the select users are members of and narrow it down that way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...