G
Guest
Hello,
I have a shared Access Database Application(.mdb) on the network drive and
the workgroup information file (.mdw) in the same folder. I follow the
article of "What are the steps to help protect a database" on
http://support.microsoft.com/?scid=http://support.microsoft.com/support/access/content/secfaq.asp
to implement the user level security on the application. Especially I remove
group member of "Admins" for user "admin" and add a password for "admin"
user, also I
did not give any permissions to group "Users" when I run the security wizard.
Then I have all the users to join the database using the workgroup
information file(Mysystem.mdw) and it works very well, I mean the permissions
on the form/query... But with the users who did not join the workgroup
informatin file(they use their default system.mdw provided by Access), as far
as they have the write permissions on the network folder where the database
application(.mdb) stored they can open the database as Admin(without any
password) by using the default workgroup info file(system.mdw) regardless of
the security settings in the secured workgroup information
file(Mysystem.mdw).And they are the Admin and have all the power on the
database... Oh, my god....what a joke...
Even though it has been pointed out on the page and the cure has been
provided, to create a new, empty database while logged on as a member of the
Admins group and import all of the objects from the security-enhanced
database, I already tried that but it did not work....
Any comments and solutions is appreciated!!!
I have a shared Access Database Application(.mdb) on the network drive and
the workgroup information file (.mdw) in the same folder. I follow the
article of "What are the steps to help protect a database" on
http://support.microsoft.com/?scid=http://support.microsoft.com/support/access/content/secfaq.asp
to implement the user level security on the application. Especially I remove
group member of "Admins" for user "admin" and add a password for "admin"
user, also I
did not give any permissions to group "Users" when I run the security wizard.
Then I have all the users to join the database using the workgroup
information file(Mysystem.mdw) and it works very well, I mean the permissions
on the form/query... But with the users who did not join the workgroup
informatin file(they use their default system.mdw provided by Access), as far
as they have the write permissions on the network folder where the database
application(.mdb) stored they can open the database as Admin(without any
password) by using the default workgroup info file(system.mdw) regardless of
the security settings in the secured workgroup information
file(Mysystem.mdw).And they are the Admin and have all the power on the
database... Oh, my god....what a joke...
Even though it has been pointed out on the page and the cure has been
provided, to create a new, empty database while logged on as a member of the
Admins group and import all of the objects from the security-enhanced
database, I already tried that but it did not work....
Any comments and solutions is appreciated!!!