- Open Local Security Settings.
- In the console tree, click User Rights Assignment.
Where?
- Security Settings/Local Policies/User Rights Assignments
- In the details pane, double-click the user right you want to change.
- In UserRight Properties, click Add User or Group.
- Add the user or group and click OK.
Note
- To open Local Security Policy, click Start, point to Settings, click Control Panel, double-click Administrative Tools, and then double-click Local Security Policy.
- Open WMI Control.
- In the console tree, right-click WMI Control, and then click Properties.
- Click the Security tab.
- Select the namespace for which you want to give a user or group access, and then click Security.
- In the Security dialog box, click Add.
- In the Select Users, Computers, or Groups dialog box, enter the name of the object (user or group) that you want to add. Click the Check Names button to verify your entry and then click OK. You might have to change the location or use the Advanced button to query for objects. See the dialog box help for more details.
- In the Security dialog box, under Permissions, select the permissions to allow or deny the new user or group.
Notes
- To perform this procedure, you must be a member of the Administrators group on the local computer, or you must have been delegated the appropriate authority. If the computer is joined to a domain, members of the Domain Admins group might be able to perform this procedure. As a security best practice, consider using Run as to perform this procedure.
- To open the WMI Control console, click Start, click Run, type wmimgmt.msc, and then click OK.
- You can set permissions on a remote computer or a local computer. To access a remote computer, right-click WMI Control, click Connect to another computer, clickAnother computer, and then type the name of the computer to which you want to connect. If you are using WMI Control from the Computer Management console, right-click the Computer Management node to connect to the other computer.
- On computers running Windows 95, Windows 98, or Windows ME, all users have full control locally. Security settings are only relevant for remote connection to a computer running Windows 95, Windows 98, or Windows ME.
- You can delete a user's or group's authorization to access WMI services by selecting that user or group and clicking Remove.
- Open Terminal Services Configuration.
- In the console tree, click Connections.
- In the details pane, right-click the connection for which you want to change permissions, and then click Properties.
- On the Permissions tab, click Advanced to open the Advanced Security Settings dialog box.
- In Permission Entries, select the user or group for which you want to change permissions, and then click Edit... to open the Permission Entry dialog box.
- In Permissions, select or clear, as appropriate, the Allow or Deny check boxes next to the permissions you want to set for the group.
Notes
- To perform this procedure, you must be a member of the Administrators group on the local computer, or you must have been delegated the appropriate authority. If the computer is joined to a domain, members of the Domain Admins group might be able to perform this procedure. As a security best practice, consider using Run as to perform this procedure. For more information, see Default local groups, Default groups, and Using Run as.
- To open Terminal Services Configuration, click Start, click Control Panel, double-click Administrative Tools, and then double-click Terminal Services Configuration.
- You must use the Remote Desktop Users group to control remote access to Terminal Server and Remote Desktop for Administration.
- Open Printers and Faxes.
- Right-click the printer for which you want to set permissions, click Properties, and then click the Security tab.
- Do one of the following:
- To change or remove permissions from an existing user or group, click the name of the user or group.
- To set up permissions for a new user or group, click Add. In Select Users, Computers, or Groups, type the name of the user or group you want to set permissions for, and then click OK to close the dialog box.
- In Permissions, click Allow or Deny for each permission you want to allow or deny, if necessary. Or, to remove the user or group from the permissions list, click Remove.
Notes
- To change device settings, you must have the Manage Printers permission. For information about printing security permissions, see Related Topics.
- To open Printers and Faxes, click Start, and then click Printers and Faxes.
- To view or change the underlying permissions that make up Print, Manage Printers, and Manage Documents, click the Advanced button.
- A printer must be shared in order for the permission settings to affect the users and groups listed.
- You can also view the permissions assigned to you by clicking the group you belong to on the Security tab. For information on finding out what group you belong to, see Related Topics.
- Open Registry Editor.
- Click the key to which you want to assign permissions.
- On the Edit menu, click Permissions.
- Assign an access level to the selected key as follows:
- To grant the user permission to read the key contents, but not save any changes made to the file, under Permissions for name, for Read, select the Allow check box.
- To grant the user permission to open, edit, and take ownership of the selected key, under Permissions for name, for Full Control, select the Allow check box.
- To grant the user special permission in the selected key, click Advanced.
- If you are assigning permissions to a subkey and you want the inheritable permissions assigned to the parent key to apply to the subkey also, click Advanced and select theInherit from parents the permission entries that apply to child objects. Include these with entries explicitly defined here check box.
Caution
- Incorrectly editing the registry may severely damage your system. Before making changes to the registry, you should back up any valued data on your computer.
Notes
- To open Registry Editor, click Start, click Run, type regedit, and then click OK.
- You must have appropriate permissions to make changes to a registry key. To maintain security when making changes to a registry key for which you need administrative credentials, log in as a member of the Users group and run Regedit as an administrator by right-clicking the Regedit icon, clicking Run as, and clicking an account in the local Administrators group. The Regedit icon does not appear by default from the Start menu. To access the icon, open the Windows or WINNT folder on your computer.
- If you own a registry key, you can specify the users and groups that can open that key. To determine who can open your registry keys, you need to assign permissions to them. You can add or remove users or groups from those authorized to access your registry keys at any time.
- The Special Permissions check boxes indicate whether custom permissions have been set for this key, but you cannot set special permissions by clicking these check boxes. Click Advanced to set special permissions.
Using Shared Folders
- To open a Control Panel item, click Start, click Control Panel, and then double-click the appropriate icon.
- In the console tree, click Shares.
Where?
- Computer Management/System Tools/Shared Folders/Shares
- In the details pane, right-click the shared resource that you want to set permissions for, and then click Properties.
- On the Share Permissions tab, make any of the following changes, and then click OK:
- To assign permissions to a user or group for a shared resource, click Add. In the Select Users, Computers, or Groups dialog box, look for or type the user or group name, and then click OK.
- To revoke access to the shared resource, click Remove.
- To set individual permissions for the user or group, in the Permissions forgroup or user box, select the Allow or Deny check boxes.
Note
- To open Computer Management, click Start, click Control Panel, double-click Administrative Tools, and then double-click Computer Management.
Using Windows Explorer
- Open Windows Explorer.
- Right-click the shared folder or drive that you want to set permissions for, and then click Sharing and Security.
- On the Sharing tab, click Permissions, make any of the following changes, and then click OK:
- To assign permissions to a user or group for a shared resource, click Add. In the Select Users, Computers, or Groups dialog box, look for or type the user or group name, and then click OK.
- To revoke access to a shared resource, click Remove.
- To set individual permissions for the user or group, in the Permissions for group or user box, select the Allow or Deny check boxes.
Note
- To open a Control Panel item, click Start, click Control Panel, and then double-click the appropriate icon.
Important
- Share permissions apply only to users who gain access to the resource over the network. They do not apply to users who log on locally, such as on a terminal server. In these cases, use access control on the NTFS file system to set permissions. For more information, see Related Topics.
Notes
- You must be logged on as a member of the Administrators group, Server Operators group, or Power Users group to complete this procedure. If your computer is connected to a network, network policy settings might also prevent you from completing this procedure.
- You can use Shared Folders to manage shared resources on both local and remote computers. For information about how to connect to another computer, see Related Topics. With Windows Explorer and the command line, you can manage shared resources on your local computer only.
- When permissions have been assigned both to the shared resource and at the file system level, the more restrictive permission always applies.
- It is usually easier to assign permissions to groups and then add users to groups, rather than assigning identical permissions to individual users.
- If you change permissions on special shared resources, such as ADMIN$, the default settings may be restored when the Server service is stopped and restarted or when the computer is restarted. Note that this does not apply to user-created shared resources whose share name ends in $. For more information about special shared resources, see Related Topics.
- File sharing options may be limited if simple file sharing is enabled. For more information about simple file sharing, see article Q304040, "How to configure file sharing in Windows XP," in the Microsoft Knowledge Base.
- Open Windows Explorer.
- Right-click the file or folder for which you want to set permissions, click Properties, and then click the Security tab.
- Do one of the following:
- To set permissions for a group or user that does not appear in the Group or user names box, click Add. Type the name of the group or user you want to set permissions for and then click OK.
- To change or remove permissions from an existing group or user, click the name of the group or user.
- Do one of the following:
- To allow or deny a permission, in the Permissions for User or Group box, select the Allow or Deny check box.
- To remove the group or user from the Group or user names box, click Remove.
Notes
- To open Windows Explorer, click Start, point to All programs, point to Accessories, and then click Windows Explorer.
- In the Windows Server 2003 family, the Everyone group no longer includes Anonymous Logon.
- You can only set file and folder permissions on drives formatted to use NTFS.
- To change permissions, you must be the owner or have been granted permission to do so by the owner.
- Groups or users that are granted Full Control for a folder can delete files and subfolders within that folder, regardless of the permissions that protect the files and subfolders.
- If the check boxes under Permissions for User or Group are shaded or if the Remove button is unavailable, then the file or folder has inherited permissions from the parent folder. For more information on how inheritance affects files and folders, see Related Topics.
- When adding a new user or group, by default, this user or group will have Read & Execute, List Folder Contents, and Read permissions.