NTFS on Domain Controllers

  • Thread starter Thread starter Brett
  • Start date Start date
B

Brett

I am looking for a white paper or artice on how to set the
NTFS permissions on a w2k3 domain controller. I would
like to remove the everyone group from NTFS. I am also
looking for security information AD objects any articles
are appreciated.

Brett
 
Please clarify a bit more on what you're trying to do here. The everyone
group can be removed from most anything as long as whatever requires it is
granted access as well (system, group1, group2, admins, users, etc) but
exactly where are you wanting to remove "Everyone".

--
David Brandt
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
 
I am trying to create a secure ntfs AD installtion that
does not have erroneous entries on it. Can I ACL with
just Administrators and System on a DC or does aDomain
Users need ntfs access.

Thnaks
 
It depends on what files/folders on that dc you're trying to restrict. For
instance users need to be able to get to Sysvol in order to get policies
etc.
If you want to remove the Everyone group from folders, you can, provided
that you then substitute the appropriate users or group/s explicitly that
will need access there.

--
David Brandt
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
 
Back
Top