"Will" <(E-Mail Removed)> wrote in message
news:WZ-(E-Mail Removed)...
> Right, I do see the grants on file system objects. That's what made it
> all
> the more strange that they would have any grants to SYSTEM be implicit on
> User Rights.
>
I think we are playing language tag again, as I don't understand "any grants
to
System be implicit on User Rights". System is a (hidden) member of
Adminsitrators,
that is all (note: this is not user rights). So, where System but not
Administrators
has need for a grant, then you will see it granted. Apparently, over time
people
have come to not know of this however and so you will find many using side
by
side identical grants to System and to Administrators.
>
> "Roger Abell [MVP]" <(E-Mail Removed)> wrote in message
> news:u46jeb$(E-Mail Removed)...
>> PS. There are explicit grants to System however, but easy to not notice.
>> Look for example at NTFS grants on System Volume Information, or
>> registry at HKLM\Security.
>
>
|