Can not find the source of Grant permission on a folder
- by Konrads
I have a security mystery :) Effective permissions tab shows that a few sampled users (IT ops) have any and all rights (all boxes are ticked). The permissions show that Local Administrators group has full access and some business users have too of which the sampled users are not members of. Local Administrators group has some AD IT Ops related groups of which the sampled users, again, appear not be members. The sampled users are not members of Domain Administrators either. I've tried tracing backwards (from permissions to user) and forwards (user to permission) and could not find anything. At this point, there are two options:
I've missed something and they are members of some groups.
There's another way of getting full permissions.
Effective Permissions are horribly wrong.
Is there a way to retrieve the decision logic of Effective Permissions? Any hints, tips, ideas?