Is their any security issues with the user rights and permissions granted tot the Everyone group on a Windows NT 4.0 Server? Or, is this really primarily a clean-up issue. I have an auditor telling me it is security issue and when I don't believe it so.
Yes this is a security issue. For example you have a shared folder on your server that only user a needs access to, user b does not need to have access. You assign the everyone group full control say on that share and user b gets access as well as user a.
What you should be doing is creating a new local group, adding the relevant user to that group and assigning the permissions to the resource based on the local group you have created and remove the everyone group (would recommend that you also add the administrators group to the share permissions).
Would the same risk exist if the only accounts residing on the server are Administrator equivalents and the machine is standalone. No shares exists on the server.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.