Jump to content

Question on Local Users Group on Windows 2003 Standalone & System3


Recommended Posts

Posted

We have a Windows 2003 server that will be placed in DMZ as a standalone

server with IIS for webpage. One of the vulnerabilities identified is the

permission settings on the IISADMPWD. It's recommended that if the directory

cannot be removed, then modify the permissions so that only the

Administrators & System have access to this folder. I noticed the Power Users

& Users group had access to this folder but were inherited from the

\system32\ folder. I removed the Power Users group from \system32\ as their

are no local user accounts in that group. However,when I look at the Users

group, I see the ASPNet, NT Authority\Authenticated Users, NT

Authority\Interactive accounts in their. If I remove the Users group from the

NTFS permissions on the \system32\ will that break access for some of these

accounts? The only users that will log on locally to this box are

administrators. There is no printing or file & print sharing.

 

I know I can just go to the IISADMPWD folder and deny access to the users.

But wanted to know if anything would break by removing the group from the

\system32\.

 

Thanks in advance for any help given.

  • Replies 3
  • Created
  • Last Reply

Popular Days

Guest Shenan Stanley
Posted

Mark wrote:<span style="color:blue">

> We have a Windows 2003 server that will be placed in DMZ as a

> standalone server with IIS for webpage. One of the vulnerabilities

> identified is the permission settings on the IISADMPWD. It's

> recommended that if the directory cannot be removed, then modify

> the permissions so that only the Administrators & System have

> access to this folder. I noticed the Power Users & Users group had

> access to this folder but were inherited from the system32

> folder. I removed the Power Users group from system32 as their

> are no local user accounts in that group. However,when I look at

> the Users group, I see the ASPNet, NT AuthorityAuthenticated

> Users, NT AuthorityInteractive accounts in their. If I remove the

> Users group from the NTFS permissions on the system32 will that

> break access for some of these accounts? The only users that will

> log on locally to this box are administrators. There is no printing

> or file & print sharing.

>

> I know I can just go to the IISADMPWD folder and deny access to the

> users. But wanted to know if anything would break by removing the

> group from the system32.

>

> Thanks in advance for any help given.</span>

 

Break inheritance and do only what is needed.

 

--

Shenan Stanley

MS-MVP

--

How To Ask Questions The Smart Way

http://www.catb.org/~esr/faqs/smart-questions.html

Guest Kerry Brown
Posted

"Mark" <Mark@discussions.microsoft.com> wrote in message

news:2CDEF17C-F821-4072-A360-CDAF22C2D104@microsoft.com...<span style="color:blue">

> We have a Windows 2003 server that will be placed in DMZ as a standalone

> server with IIS for webpage. One of the vulnerabilities identified is the

> permission settings on the IISADMPWD. It's recommended that if the

> directory

> cannot be removed, then modify the permissions so that only the

> Administrators & System have access to this folder. I noticed the Power

> Users

> & Users group had access to this folder but were inherited from the

> system32 folder. I removed the Power Users group from system32 as

> their

> are no local user accounts in that group. However,when I look at the Users

> group, I see the ASPNet, NT AuthorityAuthenticated Users, NT

> AuthorityInteractive accounts in their. If I remove the Users group from

> the

> NTFS permissions on the system32 will that break access for some of

> these

> accounts? The only users that will log on locally to this box are

> administrators. There is no printing or file & print sharing.

>

> I know I can just go to the IISADMPWD folder and deny access to the users.

> But wanted to know if anything would break by removing the group from the

> system32.

>

> Thanks in advance for any help given.</span>

 

Deny permissions are almost always a bad idea. Don't modify \system32\ Only

modify the folders that need permissions changed. You will have to break

inheritance on the folders you change. Inheritance should normally flow to

folders below the changes, but not from above.

 

--

Kerry Brown

MS-MVP - Windows Desktop Experience: Systems Administration

http://www.vistahelp.ca/phpBB2/

Posted

Re: Question on Local Users Group on Windows 2003 Standalone & Sys

 

All, thanks for your responses.

 

"Kerry Brown" wrote:

<span style="color:blue">

>

> "Mark" <Mark@discussions.microsoft.com> wrote in message

> news:2CDEF17C-F821-4072-A360-CDAF22C2D104@microsoft.com...<span style="color:green">

> > We have a Windows 2003 server that will be placed in DMZ as a standalone

> > server with IIS for webpage. One of the vulnerabilities identified is the

> > permission settings on the IISADMPWD. It's recommended that if the

> > directory

> > cannot be removed, then modify the permissions so that only the

> > Administrators & System have access to this folder. I noticed the Power

> > Users

> > & Users group had access to this folder but were inherited from the

> > system32 folder. I removed the Power Users group from system32 as

> > their

> > are no local user accounts in that group. However,when I look at the Users

> > group, I see the ASPNet, NT AuthorityAuthenticated Users, NT

> > AuthorityInteractive accounts in their. If I remove the Users group from

> > the

> > NTFS permissions on the system32 will that break access for some of

> > these

> > accounts? The only users that will log on locally to this box are

> > administrators. There is no printing or file & print sharing.

> >

> > I know I can just go to the IISADMPWD folder and deny access to the users.

> > But wanted to know if anything would break by removing the group from the

> > system32.

> >

> > Thanks in advance for any help given.</span>

>

> Deny permissions are almost always a bad idea. Don't modify system32 Only

> modify the folders that need permissions changed. You will have to break

> inheritance on the folders you change. Inheritance should normally flow to

> folders below the changes, but not from above.

>

> --

> Kerry Brown

> MS-MVP - Windows Desktop Experience: Systems Administration

> http://www.vistahelp.ca/phpBB2/

>

>

>

>

> </span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...