70-270: MCSE Guide to Microsoft Windows XP Professional (MCSE/MCSA Guides)

When you assign or modify NTFS permissions to files and folders, problems might arise. When you copy or move files and folders, the permissions you set on the files or folders might change. Specific rules control how and when permissions change. Understanding these rules helps you solve permissions problems. Troubleshooting these problems is important to keep resources available for the appropriate users and protected from unauthorized users.


After this lesson, you will be able to

Estimated lesson time: 50 minutes


Copying Files and Folders

When you copy files or folders from one folder to another or from one volume to another, permissions change, as shown in Figure 8.7.

Figure 8.7 Copying files or folders between folders or volumes

When you copy a file within a single NTFS volume or between NTFS volumes, note the following:

When you copy files or folders to FAT volumes, the folders and files lose their NTFS permissions because FAT volumes don't support NTFS permissions.

Moving Files and Folders

When you move a file or folder, permissions might or might not change, depending on where you move the file or folder (see Figure 8.8).

Figure 8.8 Moving files or folders between folders or volumes

Moving Within a Single NTFS Volume

When you move a file or folder within a single NTFS volume, note the following:

Moving Between NTFS Volumes

When you move a file or folder between NTFS volumes, note the following:

When you move files or folders to FAT volumes, the folders and files lose their NTFS permissions because FAT volumes don't support NTFS permissions.

Troubleshooting Permissions Problems

Table 8.7 describes some common permissions problems that you might encounter and provides solutions that you can use to try to resolve these problems.

Table 8.7 Permissions Problems and Troubleshooting Solutions

Problem Solution

A user can't gain access to a file or folder.

If the file or folder was copied moved to or another NTFS volume, the permissions might have changed.

Check the permissions that are assigned to the user account and to groups to which the user belongs. The user might not have permission or might be denied access either individually or as a member of a group.

You add a user account to a group to give that user access to a file or folder, but the user still can't gain access.

For access permissions to be updated to include the new group to which you have added the user account, the user must either log off and then log on again or close all network connections to the computer on which the file or folder resides and then make new connections.

A user with Full Control permission to a folder deletes a file in the folder, although that user doesn't have permission to delete the file, itself. You want to stop the user it from being able to delete more files.

You have to clear the special access permission, the Delete Subfolders And Files check box for that folder to prevent users with Full Control of the folder from being able to delete files in.

Windows XP Professional supports Portable Operating System Interface for UNIX (POSIX) applications that are designed to run on UNIX. On UNIX systems, Full Control permission allows you to delete files in a folder. In Windows 2000, the Full Control permission includes the Delete Subfolders and Files special access permission, allowing you the same ability to delete files in that folder regardless of the permissions that you have for those files.

Avoiding Permissions Problems

The following list provides best practices for implementing NTFS permissions. These guidelines will help you avoid permission problems.

Practice: Managing NTFS Permissions

In this practice, you will observe the effects of taking ownership of a file. Then you will determine the effects of permission and ownership when you copy or move files. Finally, you will determine what happens when a user with Full Control permission to a folder has been denied all access to a file in that folder but attempts to delete the file.

To successfully complete this practice, you must have completed "Practice: Planning and Assigning NTFS Permissions" in Lesson 2 of this chapter.

Exercise 1: Taking Ownership of a File

In this exercise, you observe the effects of taking ownership of a file. To do this, you must determine permissions for a file, assign the Take Ownership permission to a user account, and then take ownership as that user.

To determine the permissions for a file

  1. Log on as Fred or with a user account that is a member of the Administrators group, and then start Windows Explorer.
  2. In the Public folder, create a text document named OWNER.
  3. Right-click OWNER, and then click Properties.

    Microsoft Windows XP Professional displays the Owner Properties dialog box with the General tab active.

  4. Click the Security tab to display the permissions for the OWNER file.
  5. Click Advanced.

    Windows XP Professional displays the Advanced Security Settings For Owner dialog box with the Permissions tab active.

  6. Click the Owner tab.

    Who is the current owner of the OWNER file?

To assign permission to a user to take ownership

  1. In the Advanced Security Settings For Owner dialog box, click the Permissions tab.
  2. Click Add.

    Windows XP Professional displays the Select User Or Group dialog box.

  3. In the From This Location text box at the top of the dialog box, ensure that your computer (PRO1) is selected.
  4. In the Enter The Object Names To Select text box, type User81, and then click Check Name.

    PRO1\User81 should now appear in the Enter The Object Names To Select text box indicating that Windows XP Professional located User81 on PRO1 and it is a valid user account.

  5. Click OK.

    Windows XP Professional displays the Permission Entry For Owner dialog box. Notice that all of the permission entries for User81 are blank.

  6. Under Permissions, select the Allow check box next to Take Ownership.
  7. Click OK.

    Windows XP Professional displays the Advanced Security Settings For Owner dialog box with the Permissions tab selected.

  8. Click OK to return to the Owner Properties dialog box.
  9. Click OK to apply your changes and close the Owner Properties dialog box.
  10. Close Windows Explorer, and then log off Windows XP Professional.

To take ownership of a file

  1. Log on as User81, and then start Windows Explorer.
  2. Expand the Public folder.
  3. Right-click OWNER and then click Properties.

    Windows XP Professional displays the Owner Properties dialog box with the General tab active.

  4. Click the Security tab to display the permissions for OWNER.

    Windows XP Professional displays the Owner Properties dialog box with the Security tab active.

  5. Click Advanced to display the Advanced Security Settings For Owner dialog box, and then click the Owner tab.
  6. Under Change Owner To, select User81, and then click Apply.

    Who is now the owner of the OWNER file?

  7. Click OK to close the Advanced Security Settings For Owner dialog box.
  8. Click OK to close the Owner Properties dialog box.

To test permissions for a file as the owner

  1. While you are logged on as User81, assign User81 the Full Control permission for the OWNER text document and click Apply.
  2. Click Advanced and clear the Inherit From Parent The Permission Entries That Apply To Child Objects check box.
  3. In the Security dialog box, click Remove.
  4. Click OK to close the Advanced Security Settings For Owner dialog box.
  5. Click OK to close the Owner Properties dialog box.
  6. Delete the OWNER text document.

Exercise 2: Copying and Moving Folders

In this exercise, you see the effects of permissions and ownership when you copy and move folders.

To create a folder while logged on as a user

  1. While you are logged on as User81, in Windows Explorer, in the root folder of drive C, create a folder named Temp1.

    What are the permissions that are assigned to the folder?

    User or group Permissions

    Who is the owner? Why?

  2. Close all applications, and then log off Windows XP Professional.

To create a folder while logged on as a member of the Administrators group

  1. Log on as Administrator, or as a user account that is a member of the Administrators group, and then start Windows Explorer.
  2. In the root folder of drive C, create the folders Temp2 and Temp3.

    What are the permissions for the Temp2 and Temp3 folders that you just created?

    User or group Permissions

    Who is the owner of the Temp2 and Temp3 folders? Why?

  3. Assign the following permissions to the Temp2 and Temp3 folders. Clear the Inherit From Parent The Permission Entries That Apply To Child Objects check box. When prompted, click Remove to remove all permissions except those explicitly set.

Folder Assign these permissions

Temp2

Administrators: Full Control Users: Read & Execute

Temp3

Administrators: Full Control Backup Operators: Read & Execute Users: Full Control

To copy a folder to another folder within a Windows XP Professional NTFS volume

  1. While logged on with an account that is a member of the Administrators group, in Windows Explorer, copy C:\Temp2 to C:\Temp1 by selecting C:\Temp2, holding down Ctrl, and then dragging C:\Temp2 to C:\Temp1.

    Because this is a copy, C:\Temp2 and C:\Temp1\Temp2 should both exist.

  2. Select C:\Temp1\Temp2, and then compare the permissions and ownership with C:\Temp2.

    Who is the owner of C:\Temp1\Temp2 and what are the permissions? Why?

To move a folder within the same NTFS volume

  1. Log on as User81.
  2. In Windows Explorer, select C:\Temp3, and then move it to C:\Temp1.

    What happens to the permissions and ownership for C:\Temp1\Temp3? Why?

  3. Close all windows and log off.

Exercise 3: Deleting a File with All Permissions Denied

In this exercise, you use the Temp3 folder for which the Users group has been given Full Control permission. You create a file in the Temp3 folder but deny all permissions to that file. You then observe what happens when a user attempts to delete that file.

To create a file and deny access to it

  1. Log on with a user account that is a member of the Administrators group.
  2. In the C:\Temp1\Temp3 folder, create a text document named NOACCESS.
  3. Deny the Users group the Full Control permission for the NOACCESS text document.

    Windows XP Professional displays a Security dialog box with the following message:

    You are setting a deny permissions entry. Deny entries take

    precedence over allow entries. This means that if a user is a member

    of two groups, one that is allowed a permission, and another that is

    denied the same permission, the user is denied that permission.

    Do you want to continue?

  4. Click Yes to apply your changes and close the Security dialog box.
  5. Click OK to close the NoAccess Properties dialog box.

To view the result of the Full Control permission being denied for a folder

  1. In Windows Explorer, double-click the NOACCESS text document in the Temp3 folder to open it.

    Were you successful? Why or why not?

  2. Click Start and then click Run.

    Windows XP Professional displays the Run dialog box.

  3. Type cmd in the Open text box and click OK.
  4. Change to C:\Temp1\Temp3.
  5. Type Del NOACCESS.TXT and press Enter.

    Were you successful? Why or why not?

    How would you prevent users with Full Control permission for a folder from deleting a file in that folder for which they have been denied the Full Control permission?

Lesson Review

The following questions will help you determine whether you have learned enough to move on to the next lesson. If you have difficulty answering these questions, review the material in this lesson before beginning the next chapter. The answers are in Appendix A, "Questions and Answers."

  1. Which of the following statements about copying a file or folder are correct? (Choose all answers that are correct.)
    1. When you copy a file from one folder to another folder on the same volume, the permissions on the file do not change.
    2. When you copy a file from a folder on an NTFS volume to a folder on a FAT volume, the permissions on the file do not change.
    3. When you copy a file from a folder on an NTFS volume to a folder on another NTFS volume, the permissions on the file match those of the destination folder.
    4. When you copy a file from a folder on an NTFS volume to a folder on a FAT volume, the permissions are lost.

  2. Which of the following statements about moving a file or folder are correct? (Choose all answers that are correct.)
    1. When you move a file from one folder to another folder on the same volume, the permissions on the file do not change.
    2. When you move a file from a folder on an NTFS volume to a folder on a FAT volume, the permissions on the file do not change.
    3. When you move a file from a folder on an NTFS volume to a folder on another NTFS volume, the permissions on the file match those of the destination folder.
    4. When you move a file from a folder on an NTFS volume to a folder on the same volume, the permissions on the file match those of the destination folder.

  3. When you assign NTFS permissions you should assign the _____________________ (least/most) restrictive permissions.
  4. If you don't want a user or group to gain access to a particular folder or file, should you deny access permissions to that folder or file?

Lesson Summary

Категории