Access Control and Identity Management

Microsoft Windows Workstations and Servers

Microsoft Windows-based systems have highly granular file-based access controls. On a local level, an administrator works with users, groups, and objects. The administrator may group users together to grant rights. The administrator may control objects with both basic and advanced rights. TABLE 8-2 lists the basic access rights available in Windows and what they affect.

TABLE 8-2 Basic Access Rights in Windows
NAME DESCRIPTION FILE OR FOLDER
Full Control

Change permissions, take ownership, and delete subfolders and files.

Perform actions permitted by all other NT File System (NTFS) file or folder permissions.

Both
Modify

Delete a file or folder. ...

Get Access Control and Identity Management, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.