Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Sysvol and Netlogon Security Permissions

Reply
Thread Tools Display Modes

Sysvol and Netlogon Security Permissions

 
 
Sukhwinder Singh
Guest
Posts: n/a

 
      12-09-2009

Dear All,

I need some information on the ACL of Sysvol and Netlogon folders. We have
everyone having read in the share permission of both SYSVOL and NETLOGON. In
Share permission of Sysvol we have authenticated users having full access.
Kindly let me know if we can replace Everyone with Authenticated users and
what may be the impact of modifying the ACl of these two folders.

Thanks and Regards,
Sukhwinder Singh


 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      12-09-2009

Hello Sukhwinder,

Do not play around in the default settings of sysvol and netlogon shares
or the other folders. What you see is correct.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Dear All,
>
> I need some information on the ACL of Sysvol and Netlogon folders. We
> have everyone having read in the share permission of both SYSVOL and
> NETLOGON. In Share permission of Sysvol we have authenticated users
> having full access. Kindly let me know if we can replace Everyone with
> Authenticated users and what may be the impact of modifying the ACl of
> these two folders.
>
> Thanks and Regards,
> Sukhwinder Singh



 
Reply With Quote
 
Eric Westfall
Guest
Posts: n/a

 
      12-14-2009
Sukhwinder,

You need to consider the effective permissions of the SYSVOL directory /
share. When combining Share + NTFS permissions, remember that the most
restrictive permissions will apply. For example, by default the SYSVOL share
allows read-only access to the Everyone user context. However, the NTFS
permissions for the SYSVOL folder (C:\Windows\SYSVOL be default) restrict
read-only access to the Authenticated Users context.

So by default, only domain authenticated users will be granted read
privileges to the SYSVOL share. In theory, you could match the share
permissions to the NTFS permissions and not effect the functionality of the
SYSVOL share; however this is not recommended and wouldn't really net you any
benefits.

I hope that answers your question a little better.

--
Eric Westfall

"Sukhwinder Singh" wrote:

> Dear All,
>
> I need some information on the ACL of Sysvol and Netlogon folders. We have
> everyone having read in the share permission of both SYSVOL and NETLOGON. In
> Share permission of Sysvol we have authenticated users having full access.
> Kindly let me know if we can replace Everyone with Authenticated users and
> what may be the impact of modifying the ACl of these two folders.
>
> Thanks and Regards,
> Sukhwinder Singh
>
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Missing SYSVOL and NETLOGON Meinolf Weber [MVP-DS] Server Networking 0 11-06-2009 08:46 AM
Re: Missing SYSVOL and NETLOGON Ace Fekay [MCT] Server Networking 0 11-06-2009 07:50 AM
Re: Missing SYSVOL and NETLOGON Ace Fekay [MCT] Server Setup 0 11-06-2009 07:50 AM
Re: Hiding Sysvol and Netlogon shares? Florian Frommherz [MVP] Active Directory 0 11-05-2009 09:43 AM
Repair DNS 4010 events... Jake Windows Server 1 11-04-2009 11:20 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59