0

I’ve got a small problem. We’re using the ”Folder Redirection” feature (as a GPO) in windows server 2008R2 and that’s working as expected for all the users. It’s configured to ”Grant the user exclusive rights to documents”, for security reason. We don’t want to give every administrator right to look into other people’s home folder. As an example, a user (let’s call the user for User1) gets the following ACLs on the folder on the server:

  • CREATOR OWNER (group)
  • SYSTEM (group)
  • User1 (account)

This is as expected and no problem there. But now to the problem, when an administrator gets her/his home folder configured by windows, it’s getting:

  • CREATOR OWNER (group)
  • SYSTEM (group)
  • Administrators (group)

As a result all administrators can access each other’s home folders without a problem and this we would like to prevent. I've like to get the administrators own account as the owner of the folder, like it is with all normal users.

An administrator in our environment is a member of a group called “ADMIN” which got “Enterprise Admins” and a few other things in it.

Do anyone have the same problem? I’ve be grateful for any tips and tricks.

4

1 回答 1

0

经过更多的挖掘,我遇到了问题。我们的问题在于我们使用的应用程序(与 AD 通信的自己制作的应用程序)。所以这对其他任何人来说都不是问题,希望如此。

于 2014-12-16T13:07:36.307 回答