XP Local/domain/admin security (NTFS) issues/madness

C

Chris

I've been using Windows NT and NTFS since it's inception and I can't
remember Windows NTFS ever acting like I'm about to describe. Frankly
it's exasperating, but I also realize I'm not as "techie" as I once was,
so maybe it's just me, but...

Running Windows XP SP2 with NTFS (of course). I have a laptop which I
use to log into our corporate domain using (as an example) DOMAIN\USERA.
DOMAIN\USERA is also listed in the Administrators group of the local
machine, which I will call MACHINE. MACHINE of course is a member of
DOMAIN.

At home, I like to login using the name I use on my home network, which
I'll call MACHINE\USERB. MACHINE\USERB is also listed in the
Administrators group of the local machine.

I want either user to have COMPLETE and UNINHIBITED access to the entire
hard drive, no matter what file. In the past, under Windows NT 4.0 and
Windows 2K, being in the local Administrators group has always
accomplished this. (I'm not talking about ticky-tack prohibitions like
being able to delete the pagefile.sys, etc.)

This apparently DOES NOT work under Windows XP. I'm CONSTANTLY having
to assume ownership of files and setting NTFS permissions on files.
I've tried adding ACLs allowing DOMAIN\USERA and MACHINE\USERB full
control on all files -- the ACLs disappear. Or if I add ACLs to
specific files, the ACLs disappear.

It's absolutely maddening and seemingly ridiculous. If both users are
local admins, they should have access to the entire HD. This worked in
previous NT versions.

Can someone provide me with an answer that will grant the access I am
looking for and have it STAY that way? I can't believe XP is so
entirely different. (I suspect AD has something to do with all this.)

-ceo
 
C

Chris

Chris said:
I've been using Windows NT and NTFS since it's inception and I can't
remember Windows NTFS ever acting like I'm about to describe. Frankly
it's exasperating, but I also realize I'm not as "techie" as I once was,
so maybe it's just me, but...

Running Windows XP SP2 with NTFS (of course). I have a laptop which I
use to log into our corporate domain using (as an example) DOMAIN\USERA.
DOMAIN\USERA is also listed in the Administrators group of the local
machine, which I will call MACHINE. MACHINE of course is a member of
DOMAIN.

At home, I like to login using the name I use on my home network, which
I'll call MACHINE\USERB. MACHINE\USERB is also listed in the
Administrators group of the local machine.

I want either user to have COMPLETE and UNINHIBITED access to the entire
hard drive, no matter what file. In the past, under Windows NT 4.0 and
Windows 2K, being in the local Administrators group has always
accomplished this. (I'm not talking about ticky-tack prohibitions like
being able to delete the pagefile.sys, etc.)

This apparently DOES NOT work under Windows XP. I'm CONSTANTLY having
to assume ownership of files and setting NTFS permissions on files. I've
tried adding ACLs allowing DOMAIN\USERA and MACHINE\USERB full control
on all files -- the ACLs disappear. Or if I add ACLs to specific files,
the ACLs disappear.

It's absolutely maddening and seemingly ridiculous. If both users are
local admins, they should have access to the entire HD. This worked in
previous NT versions.

Can someone provide me with an answer that will grant the access I am
looking for and have it STAY that way? I can't believe XP is so
entirely different. (I suspect AD has something to do with all this.)

I should followup by adding that MACHINE\Administrators is in the ACL of
every file I've checked as having "Full Control" when going to edit the
ACLs or to assume file ownership. Which makes it difficult to conceive
how this could be going on. It seems meaningless to have the
Administrators group.

-ceo
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top