"Kris Shaw" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi,
>
> I suppose if you really have to deny those users you could:
>
> -Create a new security group and add those six users to it
> -Add an explicit deny to that security group on the folders they
> shouldn't have access to.
>
> I personally don't work like this -instead I start with nothing and
> add groups of users as necessary. Also, avoid the temptation to
> individually add the six users, create a group which is easier to
> maintain in the future.
>
> Kris.
I agree, i only mentioned the deny option to provide an alternative, and a
dangerous alternative at that. Its much easier / safer to manage specifying
who has the permission than who should be denied. As specified in my post,
that is not recommended.
Lets face it, how many times have i found myself before an administrator who
states that he denied local logons at a DC to the domain users group and
then stated that he couldn't logon locally as admin anymore. Duh, admin is a
member of the domain users group.
>
> On Sun, 15 Feb 2004 09:46:07 -0500, "SaltPeter"
> <(E-Mail Removed)> said to us:
>
> >"sphilip" <(E-Mail Removed)> wrote in message
> >news:10a1d01c3f3c2$d3606220$(E-Mail Removed)...
> >> i need to create 6 users in our domain but they should not
> >> be in the everyone group, due to access rights. how do i
> >> remove them from the everyone group.
> >
> >You can't do that but neither should you have any need to do so. In fact,
> >you wouldn't want them NOT to be in that group. You would essentially be
> >stating to the security provider that all security requirements that are
> >enforced on everyone do not apply to the 6 users. Can you say the words:
> >hack me, please?
> >
> >If you share a resource and choose to prevent access to the 6 users, only
> >share the resource to whatever groups don't include the 6 users. Of
course,
> >you can deny the 6 users as well. But this is not recommended because
deny
> >overides all, including a deny in the case one of the 6 is the
> >administrator.
> >
>
|