keyongtech


  keyongtech > sharepoint.* > sharepoint.setup_and_administration

 #1  
02-19-09, 01:25 AM
GTS, Inc.
When I create a new domain user account, that user has FULL
permission
without adding the new user to any SP groups. I have checked the
default group permissions, they are all default. I have checked
anonymous access, it is turned off. I have checked IIS and all
sharepoint sites are NOT set to allow anonymous access, and I have
checked POLICY FOR WEB APPLICATION.

The latter is the only thing I have found to change the site at all.
In my user list under POLICY FOR WEB APPLICATION, I have:


NT AUTHORITY\LOCAL SERVICE - FULL READ
NT AUTHORITY\NETWORK SERVICE - FULL CONTROL
NT AUTHORITY\SYSTEM - FULL CONTROL
BUILTIN\USERS - FULL CONTROL


The last one is the account that impacts site function. If I remove
it or change the permissions, it affects ALL users on the site.
 #2  
02-21-09, 05:09 AM
Daniel A. Galant
I don't know why the Builtin \Users would be granted Full Control. Web
application policies do indeed apply to the entire web application, and the
superceed any other permissions. I don't have access to a SharePoint CA at
the moment so I can't tell you what the default policy permissions are.
However, as Ben Curry points out in this blog post
http://www.mindsharpblogs.com/ben/ar...3/30/1657.aspx most of the
default permissions are Full read, not Full control. You are going to want
to modify the Web application policies and you shoud apply permissions in
the Site collections instead.
Similar Threads
Best Default security group in AD for Tech. Support For full permission

Hi guys? I have windows 2003 Domain in my office. I installed Microsoft SharePoint portal server in one of member windows 2003 server. Our all technical support users...

Any way that non-Admin group users can add like-kind users?

Has anyone come up with a scheme that would allow "power user" type logins to create like-kind and more restrictive user logins? IE, a power user that can add and edit and...

How do i give users permission to open an SMS admin console to my site?

Permission to UNLOCK a workstation and not full blown admin

Hello, I do quite a bit of work for schools. Anyway, students leave the pc's in a locked state and we want to let teachers unlock the workstation without being a full...


All times are GMT. The time now is 07:11 PM. | Privacy Policy