Setting up GPO to assign file system permissions

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Guest
Archived from groups: microsoft.public.win2000.group_policy (More info?)

I am trying to set up a policy that will assign file
permissions on a specific file (explorer.exe), in order
to restrict access to it across all of our Citrix
Metaframe servers.

To do this, I opened the default domain policy in the
Group Policy editor. I went to 'computer
configuration', 'security settings', and 'File System'. I
added the file 'c:\winnt\explorer.exe', configure deny
execute permissions for the user group I wanted to
restrict, deselected the option for the file to allow
inheritable permissions to propagate.

However, whenever I log in to the servers, no matter
which user I log in with (domain admin, regular user),
the permissions remain unchanged (everyone,fullcontrol).

Anyone out there have experience pushing NFTS permssions
via GPO's before, that can give me some direction?
 
Archived from groups: microsoft.public.win2000.group_policy (More info?)

Are your servers 2k or 2k3?

--
Derek Melber
BrainCore.Net
derekm@braincore.net
"arameth" <anonymous@discussions.microsoft.com> wrote in message
news:130f101c418ff$69fc3540$a001280a@phx.gbl...
> I am trying to set up a policy that will assign file
> permissions on a specific file (explorer.exe), in order
> to restrict access to it across all of our Citrix
> Metaframe servers.
>
> To do this, I opened the default domain policy in the
> Group Policy editor. I went to 'computer
> configuration', 'security settings', and 'File System'. I
> added the file 'c:\winnt\explorer.exe', configure deny
> execute permissions for the user group I wanted to
> restrict, deselected the option for the file to allow
> inheritable permissions to propagate.
>
> However, whenever I log in to the servers, no matter
> which user I log in with (domain admin, regular user),
> the permissions remain unchanged (everyone,fullcontrol).
>
> Anyone out there have experience pushing NFTS permssions
> via GPO's before, that can give me some direction?
>
>
>
 
Archived from groups: microsoft.public.win2000.group_policy (More info?)

All servers running Windows 2000.
>-----Original Message-----
>Are your servers 2k or 2k3?
>
>--
>Derek Melber
>BrainCore.Net
>derekm@braincore.net
>"arameth" <anonymous@discussions.microsoft.com> wrote in
message
>news:130f101c418ff$69fc3540$a001280a@phx.gbl...
>> I am trying to set up a policy that will assign file
>> permissions on a specific file (explorer.exe), in order
>> to restrict access to it across all of our Citrix
>> Metaframe servers.
>>
>> To do this, I opened the default domain policy in the
>> Group Policy editor. I went to 'computer
>> configuration', 'security settings', and 'File
System'. I
>> added the file 'c:\winnt\explorer.exe', configure deny
>> execute permissions for the user group I wanted to
>> restrict, deselected the option for the file to allow
>> inheritable permissions to propagate.
>>
>> However, whenever I log in to the servers, no matter
>> which user I log in with (domain admin, regular user),
>> the permissions remain unchanged
(everyone,fullcontrol).
>>
>> Anyone out there have experience pushing NFTS
permssions
>> via GPO's before, that can give me some direction?
>>
>>
>>
>
>
>.
>