LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

On a new folder like C:\Daten, the local Users group has "Special" permissions. What are they, and why remove Users from a data share?

Users inherits from the C:\ root the rights to create folders and create files inside the folder, on top of read and execute. On a data share, that would let every user write where they shouldn't.

The default access list on the system drive gives Users:

  • Read & execute (this folder, subfolders and files)
  • Special: Create folders / append data (this folder and subfolders)
  • Special: Create files / write data (subfolders only)

The special entries exist so that ordinary users can create their own folders on the drive. A new folder inherits them, so every user could drop files into C:\Daten\Management.

The lab therefore disables inheritance and replaces Users with the exact domain groups that should have access. That is least privilege: start from nothing and grant access deliberately, rather than inheriting a broad default.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026