On a new folder like C:\Daten, the local Users group has "Special" permissions. What are they, and why remove Users from a data share?
Users inherits from the C:\ root the rights to create folders and create files inside the folder, on top of read and execute. On a data share, that would let every user write where they shouldn't.
The default access list on the system drive gives Users:
- Read & execute (this folder, subfolders and files)
- Special: Create folders / append data (this folder and subfolders)
- Special: Create files / write data (subfolders only)
The special entries exist so that ordinary users can create their own folders on the drive. A new folder inherits them, so every user could drop files into C:\Daten\Management.
The lab therefore disables inheritance and replaces Users with the exact domain groups that should have access. That is least privilege: start from nothing and grant access deliberately, rather than inheriting a broad default.
Go deeper:
TechNet Magazine: NTFS Permissions, Part 2 — table of all special permissions, including Create folders / append data.
Microsoft Learn: Users group — who is in the local
Usersgroup by default.