Windows 10: NTFS permissions, AD groups, and use of VPN... Unexpected behavior

Discus and support NTFS permissions, AD groups, and use of VPN... Unexpected behavior in Windows 10 Network and Sharing to solve the problem; I have a question I need help to understand. I've been in IT for 20+ years. It has always been my understanding that when adding a user to a new... Discussion in 'Windows 10 Network and Sharing' started by Matthew McDonald EWS, Apr 14, 2021.

  1. NTFS permissions, AD groups, and use of VPN... Unexpected behavior


    I have a question I need help to understand. I've been in IT for 20+ years. It has always been my understanding that when adding a user to a new Active Directory group, that group membership is not picked up until the user logs off the machine and logs back on.


    Further, this is required to refresh the user's security token so that access granted via use of this group can be allowed, for example to file servers.


    As part of my administration, any time I add a user to a group, I instruct them to log off/back on, and everything works as expected.


    Today I ran into something I can't explain. With the time of COVID and everyone working from home and over VPN, we've had numerous issues regarding the circumstances above, as our user's VPN connections occur AFTER logon, which means they can never pick up the new security token to reflect their new group memberships.


    We've had to resort to work arounds such as using tools like klist /purge or ending task on Explorer, issuing a runas on a new instance of explorer and specifying the user's AD account/password to force them to pick up the new token while the VPN is connected.


    This concept was recently challenged as unnecessary. After performing more testing myself, I am astounded by my findings and thoroughly confused.


    I have added myself to a new group tied to a file share I currently do not have access to. On my in-office desktop machine, that which I have not logged off yet, and as such I still do not have access to the share. This is expected.


    However on my laptop, I disconnected VPN, logged off, logged back on, and then reconnected VPN, and magically I have access to this share. HOW?! I have confirmed through "whoami /groups" that I still do not have the token/membership to this group, yet some how I'm authorized to access this share. I do not understand how this is possible!


    Please help me understand.

    :)
     
    Matthew McDonald EWS, Apr 14, 2021
    #1

  2. xp ntfs permissions erased - help!

    NEVER, ever, remove FULL CONTROL permissions in the Access Control Lists/rights priveleges from:

    • Administators Group
    • YOUR local Administrator User
    • SYSTEM
    on NTFS rights on your disks (via Explorer.exe rightclick properties menu, security tab) that use that filesystem, OR in the REGISTRY either, via rightclick on HIVES/KEYS permissions popup menu options...

    (Sure way to lock yourself out, period, & I have done it myself early on w/ NTFS filesystems &/or the Registry before... only way to learn sometimes, is making mistakes!)

    * Keep this in mind, those of you that start experimenting w/ security @ these 2 levels!

    APK

    P.S.=> Leaving them @ FULL POWER, in both areas, usually 9/10 times allows you to get back into your rig (logging on as your LOCAL ADMINISTRATOR USER, to fix it), & make alterations to rights/acl's as needed, to "get it right", eventually... especially when you're still learning/experimenting! apk
     
    Alec§taar, Apr 14, 2021
    #2
  3. Is this comment regarding NTFS Permissions backwards or is it just me?

    So, I'm studying for the CompTIA A+ Core 2 exam and I get this explanation about how NTFS Permissions work. Here it is:

    "Both NTFS and share permissions can be assigned to users and groups."

    It sounds a little bit backwards to me. Does one actually assign NTFS and share permissions to users and groups? Or is it more accurate to say that users and groups can be assigned to NTFS and Share permissions?

    The users and the groups get added to ACL lists. NTFS permissions do not get added to users or groups.

    I'm not trying to be a grammar nazi here. I understand what they're trying to teach. But having taken logic in the past I know that you can't just swap word positions interchangeably in every circumstance and not affect the meaning of the sentence.

    Am I right or wrong here?

    Windows local security policies work in much the same way. I used to think that users and groups had local security policies attached to the users or the groups. But it's the other way around. Users and Groups are assigned to security policy rules.
     
    ObiWanKenobi, Apr 14, 2021
    #3
  4. Knoxx29 Win User

    NTFS permissions, AD groups, and use of VPN... Unexpected behavior

    Vpn ( trusted Vpn)

    Hi everyone.
    I am not an expert about Vpn and that's why I would like to know if someone could list me a few trusted Vpns, I would really appreciate any suggestion/ advice.

    Thanks.
     
    Knoxx29, Apr 14, 2021
    #4
Thema:

NTFS permissions, AD groups, and use of VPN... Unexpected behavior

Loading...
  1. NTFS permissions, AD groups, and use of VPN... Unexpected behavior - Similar Threads - NTFS permissions groups

  2. Unexpected Windows Behavior

    in Windows 10 Gaming
    Unexpected Windows Behavior: In short: My computer randomly freezes without any warnings, and stays unresponsive until I shut it downHello Community,I have been bothered by a problem I can't entirely solve and it's haunting me for months now. Although it happens rarely I still find it weird.Every once in...
  3. Unexpected Windows Behavior

    in Windows 10 Software and Apps
    Unexpected Windows Behavior: In short: My computer randomly freezes without any warnings, and stays unresponsive until I shut it downHello Community,I have been bothered by a problem I can't entirely solve and it's haunting me for months now. Although it happens rarely I still find it weird.Every once in...
  4. NTFS Permission

    in Windows 10 Gaming
    NTFS Permission: Hello, I have created permissions on the folder share on the server and gave a specific user not to delete or delete, but I gave him permission Write Attribute and Write Extended Attribute However, I can't save to an excel sheet, but anything else works like Notepad ...........
  5. NTFS Permission

    in Windows 10 Software and Apps
    NTFS Permission: Hello, I have created permissions on the folder share on the server and gave a specific user not to delete or delete, but I gave him permission Write Attribute and Write Extended Attribute However, I can't save to an excel sheet, but anything else works like Notepad ...........
  6. NTFS Permission

    in Windows 10 Network and Sharing
    NTFS Permission: Hello, I have created permissions on the folder share on the server and gave a specific user not to delete or delete, but I gave him permission Write Attribute and Write Extended Attribute However, I can't save to an excel sheet, but anything else works like Notepad ...........
  7. NTFS permissions

    in Windows 10 Network and Sharing
    NTFS permissions: Windows 10, Windows 7 - probably all Window versions. I work in a highly regulated area and want to just save data to a Windows folder/directory that does not allow (for data integrity purposes) users to delete or modify data stored within the directory. Windows saving...
  8. NTFS Permissions...

    in Windows 10 BSOD Crashes and Debugging
    NTFS Permissions...: I am unable to change the permission of a folder. I have never come across this problem until now and it's irritating because I am unable to download steam games due to the fact my folder is stuck in read-only and every time I un-check the box and click apply, the folder...
  9. Which permissions override when using Folder permissions and NTFS permissions?

    in AntiVirus, Firewalls and System Security
    Which permissions override when using Folder permissions and NTFS permissions?: Which permissions override when using Folder permissions and NTFS permissions? https://answers.microsoft.com/en-us/windows/forum/windows_10-security/which-permissions-override-when-using-folder/ea226001-173c-49f6-afa1-0d6de9f1f4c5"
  10. DISM, unexpected behavior

    in Windows 10 Performance & Maintenance
    DISM, unexpected behavior: I am trying to use DISM for a Windows repair. I have tried to follow: DISM - Repair Windows 10 Image I downloaded an iso file (x64, my version 1511) here: Microsoft Windows 10 TH2 ISO Download • Windows ISO Where g: is the mounted iso: DISM /Online /Cleanup-Image...