| Matt G. 2004-05-14, 7:35 pm |
| I am noticing the strangest behavior on my Win2K3 server -
I configured a share - granted EVERYONE full control share access (as
recommended - limit access via NTFS).
Limited the NTFS permissions to 'Administrators-Full', System-'Full',
and Network 'Read,Execute'.
Even with these seemingly limited permissions, I can access the share
with a non-admin domain user - this obviously doesn't make sense since
the user isn't in the admin group. I deleted the 'Network' built in
account, and access was denied. If Ireapply the NETWORK account,
access is granted. The level of access for the non-domain account
mimics the access level granted to the built in Network accout on the
share.
The reason this is a problem is because we are trying to use Front
Page Server Extensions on this share... FPSE automatically adds the
NETWORK user to all subwebs, which then apparently grants access to
non-admin users, or users who don't explicitly have permissions on the
share. Very strange, and troubling. I hope I am just doing something
stupid....
PLease help!!!
-Matt
|