A bug in basic NTFS permissions?

%3CLINGO-SUB%20id%3D%22lingo-sub-1521665%22%20slang%3D%22en-US%22%3EA%20bug%20in%20basic%20NTFS%20permissions%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1521665%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%20I%20feel%20I'm%20missing%20something%20very%20basic%20here.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20new%20Win%2010%20Pro%20machine%2C%20build%201909.%26nbsp%3B%20Created%20a%20folder%20on%20C%3A%2C%20named%20DATA.%26nbsp%3B%20Under%20DATA%2C%20I%20have%20a%20subfolder%20called%20SHARED.%26nbsp%3B%20I've%20set%20SHARED%20to%20disable%20inheritance.%26nbsp%3B%20Then%20via%20the%20Advanced%20permissions%20sreen%2C%20removed%20Authenticated%20Users%20and%20Users%2C%20leaving%20only%20System%20and%20Administrators%20as%20Full%20Control%20for%20%22this%20folder%20and%20all%20sub%20items%22.%26nbsp%3B%20So%2C%20all%20default%20stuff%20so%20far.%26nbsp%3B%3C%2FP%3E%3CP%3EI%20noticed%20the%20ownership%20was%20set%20to%20my%20actual%20logged-in%20user%2C%20which%20is%20in%20the%20Administrators%20group.%20I%20changed%20the%20ownership%20to%20the%20Administrators%20group%20instead%20of%20just%20me.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EClicked%20all%20the%20OK's%20and%20what%20not.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3ENow%2C%20every%20time%20I%20go%20into%20the%20SEcurity%20tab%20for%20SHARED%2C%20I'm%20told%20I%20don't%20have%20Read%20permissions.%26nbsp%3B%20Click%20the%20Advanced%20button%20in%20the%20Security%20tab%2C%20that%20screen%20tells%20me%20it%20can't%20show%20the%20owner%20info%2C%20and%20that%20I%20need%20Read%20permissions.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20I%20click%20the%20Change%20link%20next%20to%20the%20ownership%20line%2C%20or%2C%20click%20the%20Continue%20button%20to%20grant%20myself%20Read%20permissions%2C%20all%20permissions%2Fuser%20stuff%20shows%20fine.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20familiar%20with%20the%20idea%20that%20to%20access%20certain%20resources%20on%20a%20system%20where%20permissions%20aren't%20elevated%20by%20default%20you%20have%20to%20basically%20click%20a%20Continue%20button%2C%20like%20one%20admin%20user%20accessing%20the%20Users%20profile%20folder%20of%20another%20user%20on%20the%20system%2C%20but%20I%20don't%20recall%20this%20hassle%20in%20the%20permissions%20screens.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20left%20me%20wondering%20if%20there's%20a%20bug%20is%20that%20when%20first%20going%20into%20Advanced%20via%20the%20Security%20tab%20and%20seeing%20the%20%22unable%20to%20display%20owner%22%20line%2C%20if%20I%20click%20Change%2C%20then%20just%20ESC%20the%20screen%20away%2C%20it%20shows%20me%20everything%20after%20that.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20terms%20of%20%22real%20world%22%20access%2C%20it%20turns%20out%20that%20if%20I%20try%20to%20actually%20browse%2Fdouble-click%20to%20get%20into%20the%20folder%20called%20SHARED%2C%20I'm%20met%20with%20that%20prompt%20about%20having%20not%20permissions%20and%20having%20to%20click%20Continue%20to%20get%20in.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20I%20missing%20something%20with%20how%20the%20Administrators%20group%20functions%20in%20Win%2010%3F%26nbsp%3B%20I'm%20trying%20to%20set%20this%20machine%20up%20as%20a%20basic%20file%20share%20server%20for%20a%20small%20business%2C%20so%20I%20have%20a%20half%20dozen%20user%20accounts%20created%20-%20can't%20have%20all%20the%20shares%20prompting%20users%20constantly%20with%20these%20stupid%20permissions%20screens.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEdited%20to%20add%3A%26nbsp%3B%20I%20intend%20to%20have%20further%20sets%20of%20subfolders%20up%20to%205%20levels%20down%2C%20most%20or%20all%20with%20explicit%20permissions%20and%20very%20little%20if%20any%20inheritance%20happening.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi all, I feel I'm missing something very basic here.  

I have a new Win 10 Pro machine, build 1909.  Created a folder on C:, named DATA.  Under DATA, I have a subfolder called SHARED.  I've set SHARED to disable inheritance.  Then via the Advanced permissions sreen, removed Authenticated Users and Users, leaving only System and Administrators as Full Control for "this folder and all sub items".  So, all default stuff so far. 

I noticed the ownership was set to my actual logged-in user, which is in the Administrators group. I changed the ownership to the Administrators group instead of just me.  

Clicked all the OK's and what not.  

Now, every time I go into the SEcurity tab for SHARED, I'm told I don't have Read permissions.  Click the Advanced button in the Security tab, that screen tells me it can't show the owner info, and that I need Read permissions.  

If I click the Change link next to the ownership line, or, click the Continue button to grant myself Read permissions, all permissions/user stuff shows fine.  

 

I'm familiar with the idea that to access certain resources on a system where permissions aren't elevated by default you have to basically click a Continue button, like one admin user accessing the Users profile folder of another user on the system, but I don't recall this hassle in the permissions screens.  

 

What left me wondering if there's a bug is that when first going into Advanced via the Security tab and seeing the "unable to display owner" line, if I click Change, then just ESC the screen away, it shows me everything after that.  

 

In terms of "real world" access, it turns out that if I try to actually browse/double-click to get into the folder called SHARED, I'm met with that prompt about having not permissions and having to click Continue to get in.  

 

Am I missing something with how the Administrators group functions in Win 10?  I'm trying to set this machine up as a basic file share server for a small business, so I have a half dozen user accounts created - can't have all the shares prompting users constantly with these stupid permissions screens.  

 

Edited to add:  I intend to have further sets of subfolders up to 5 levels down, most or all with explicit permissions and very little if any inheritance happening.  

0 Replies