PDA

View Full Version : User Folder Access Anomaly


Paul Komski
06-29-2003, 06:12 AM
WinXP Pro/NTFS File system/Workgroup not Domain Logon.
Two User Accounts PK (Administators), XYZ (Users).
The "PK" Folder within the "Documents and Settings" Folder is set to "Make this Folder Private".
All sub-folders within "PK" are also checked "Make this Folder Private".

Switch User and LogOn as "XYZ"
Access to PK's Documents is denied if access is attempted via the Windows Explorer Tree, eg, C:\Documents and Settings\PK\

BUT if XYZ clicks "My Computer" and then "PK's Documents" under the heading "Files Stored on This Computer" full access is given to it and to all the files and sub-folders within it!!!

Is there any fix for this; to prevent XYZ from accessing PK's files? It just seems odd that one route to the files denies access but another route allows access to the same ordinary user.

mjc
06-29-2003, 12:28 PM
In theory, if restrictions are set then another user should not be able to access the restricted files...if the second user does not have higher priveleges (like administrator).

Paul Komski
06-29-2003, 02:18 PM
Thanks mjc; that's what I thought - and have "sort of" discovered what was happening.

The My Documents (of PK) had been moved to D: (also an NTFS partition).

The "simple" file access permissions are only stated to work in XP for those folders in the System Partition and in that User's Folders within the relevant Documents and Settings Folder.

This begs the question of why access is restricted by one route and not by another - but perhaps that's of no real importance in this discussion.

After moving the My Documents Folder back to its default position under C:\Documents and Settings\PK\ the user XYZ no longer sees the "PK's Documents" Folder at all in the "Files Stored on this computer" section and can still not access the folder from the Explorer path.

So the question needs to be put differently. How does a user with Administrator rights allow access to files/folders outside the system partition only to himself/herself and prohibit access to other (non-administrator) users, when they log-on?

mjc
06-29-2003, 10:25 PM
Use a *nix OS?

Seems very strange, because there are many cases where things will get put outside the system/default locations.

Not as up on the oddities of NTFS stuff as I should be....so I'll just sit here scratching my head and if you smell smoke, you'll know from whence it comes......;)