none
Server 2012 - Domain Admin hat keinen Zugriff auf Ordner RRS feed

  • Frage

  • Hallo,

    Server 2012 - Domain Admin hat keinen Zugriff auf Ordner.

    Fehlermeldung:

    Sie haben zu zeit keinen Zugriff auf den Ordner -> Fortsetzen/Abrechen


    Über den UNC Pfad funktioniert es allerdings schon wie gewohnt.

    Danke

     


    P.P.

    Donnerstag, 20. Juni 2013 13:15

Antworten

  • Hallo Peter,

    UAC und Explorer.... 

    Explorer UAC Error when accessing folder or files although the permission is given

    This is by design. Prior to the UAC prompt the user session is running in the standard user token, which means it does not have elevated privileges. This means the 'Administrators' group cannot apply - because the session has not been elevated to grant these advanced privileges. Unfortunately the 'Continue' button does not do as you would expect and elevate, enabling the 'Administrators' group and allowing access. Instead, as an Administrator with the ability to change permissions, it will add the user accessing the data with their own ACL, which ends up getting very messy. The best solution (and the one I use) is to keep the Administrators group but then have another group, like 'IT Users', into which you place your IT users. You can then add that as another group with access permissions, and this should not have the same issue, since it would not be considered a restricted or high-security group, which the Administrators group is.

    Another solution is to use e.g. TotalCommander or another third party software to administer the fileserver. This software can be elevated to the admin token.

      Viele Grüße


    Philipp Halbedel

    MCP 2003,MCITP EA Server 2008,MCITP EA Windows 7,MCSA2008,MCSA2012 

    Meine Antwort war hilfreich? ich freu mich über eine Bewertung. If my answer was helpful, I'm glad about a rating! 

    I do not represent the organisation I work for, all the opinions expressed here are my own.

    • Als Antwort markiert PeterPichler Freitag, 21. Juni 2013 10:23
    Freitag, 21. Juni 2013 09:47

Alle Antworten

  • Hallo Peter,

    UAC und Explorer.... 

    Explorer UAC Error when accessing folder or files although the permission is given

    This is by design. Prior to the UAC prompt the user session is running in the standard user token, which means it does not have elevated privileges. This means the 'Administrators' group cannot apply - because the session has not been elevated to grant these advanced privileges. Unfortunately the 'Continue' button does not do as you would expect and elevate, enabling the 'Administrators' group and allowing access. Instead, as an Administrator with the ability to change permissions, it will add the user accessing the data with their own ACL, which ends up getting very messy. The best solution (and the one I use) is to keep the Administrators group but then have another group, like 'IT Users', into which you place your IT users. You can then add that as another group with access permissions, and this should not have the same issue, since it would not be considered a restricted or high-security group, which the Administrators group is.

    Another solution is to use e.g. TotalCommander or another third party software to administer the fileserver. This software can be elevated to the admin token.

      Viele Grüße


    Philipp Halbedel

    MCP 2003,MCITP EA Server 2008,MCITP EA Windows 7,MCSA2008,MCSA2012 

    Meine Antwort war hilfreich? ich freu mich über eine Bewertung. If my answer was helpful, I'm glad about a rating! 

    I do not represent the organisation I work for, all the opinions expressed here are my own.

    • Als Antwort markiert PeterPichler Freitag, 21. Juni 2013 10:23
    Freitag, 21. Juni 2013 09:47
  • Hallo Philipp,

    Ja das wars

    Danke sehr

    lg

    peter


    P.P.

    Freitag, 21. Juni 2013 10:24