Jump to content

Recommended Posts

Posted

Hi

 

I've been asked to "investigate the feasibility of changing the file/folder permissions on home and shared folders so that only the relevant user(s) have permissions to the files/folders i.e. remove the Administrators/other groups permissions".

 

I'm not sure if it is a good idea removing the admins group from an admin / data management perspective but I would like some advice on the impact of doing this, and an insight into how other schools tech manage this.

 

Many thanks

Posted
If you're removing all admins groups, you might find your backup system struggles to backup the files.

 

Thanks Meldrew, Should have mentioned we are using Veeam & I've tested that this is working on a folder with the permissions removed.

Posted
Hi

 

I've been asked to "investigate the feasibility of changing the file/folder permissions on home and shared folders so that only the relevant user(s) have permissions to the files/folders i.e. remove the Administrators/other groups permissions".

 

I'm not sure if it is a good idea removing the admins group from an admin / data management perspective but I would like some advice on the impact of doing this, and an insight into how other schools tech manage this.

 

Many thanks

 

You need should allow Domain Admins, and any accounts needed for backup/restore purposes.

 

Permissions will need to be modified at some point, even moving files folders to new servers will require some degree of permissions.

 

You could take ownership of files and do it that way but this would muck up any Quota allowances unless you re-assign ownership.

 

I wouldn't allow end users to change permissions on their own folders either to be honest.

  • Thanks 1
Posted

In addition to the comments about backup and migration, will virus scans still work if domain admin permissions are revoked? Would disk quotas continue to be enforced if the system couldn't view and enumerate the contents of a folder?

 

If someone copied a massive amount of data into one of these folders and this prevented others from saving work, how would you respond? Here, I might remove that folder to restore access while waiting to speak to the owner about a way to store the data appropriately. You couldn't do that if you don't have admin rights. Heck, would you even be able to identify which folder was the massive one?

 

Is it even possible to remove your own rights from a shared network folder??

 

I would be interested to know why you're being asked to do this. Are there concerns over IT support staff having access to everyone's files? Is there a particular uber-confidential file/folder which Leadership are concerned about? If so, you could make the change on the specific folder but explain the risks first. Or get them an encrypted memory stick. Is the solution to this non-technical, and making all IT admins sign something to confirm they will only view files as their job requires, and/or only with explicit prior consent when viewing Leadership's files.

  • Thanks 1
Posted
In addition to the comments about backup and migration, will virus scans still work if domain admin permissions are revoked? Would disk quotas continue to be enforced if the system couldn't view and enumerate the contents of a folder?

 

If someone copied a massive amount of data into one of these folders and this prevented others from saving work, how would you respond? Here, I might remove that folder to restore access while waiting to speak to the owner about a way to store the data appropriately. You couldn't do that if you don't have admin rights. Heck, would you even be able to identify which folder was the massive one?

 

Is it even possible to remove your own rights from a shared network folder??

 

I would be interested to know why you're being asked to do this. Are there concerns over IT support staff having access to everyone's files? Is there a particular uber-confidential file/folder which Leadership are concerned about? If so, you could make the change on the specific folder but explain the risks first. Or get them an encrypted memory stick. Is the solution to this non-technical, and making all IT admins sign something to confirm they will only view files as their job requires, and/or only with explicit prior consent when viewing Leadership's files.

 

Hi Enjay,

 

Thanks for your response, these are all concerns I have also, and have put together a document to highlight this. There is a security review going on and other than this I have no further info other than to investigate the feasibility and impact of doing this.

Posted

We're currently in the process of reviewing our network permission, with a view to undertake the reverse of what you're looking to do. All our staff areas are permissioned to give the user exclusive access to their folders.

 

We have a real problems supporting the users on a day-to-day basis. We're unable to provide remote support on document issues due to no access. The user has restricted access to the desktop due to GP's, which make it hard for us to do anything while logged on as the user.

 

We're looking to propose creation of a new security group which, along with the end user and system, will have permissions to access folders. Access to this group will be restricted and auditing placed on it.

 

As a side note, if you think about it, as a domain admin you have the ability to reset someones password and thus gain access to their documents.

 

Did someone famous once say, with great power comes great responsibility? If not, then they should have :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...