<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; ACL</title>
	<atom:link href="http://www.winadmin.ro/tag/acl/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Fri, 03 Feb 2012 19:33:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Copy files between servers &amp; retaining security permissions</title>
		<link>http://www.winadmin.ro/2011/11/22/copy-files-between-servers-retaining-security-permissions/</link>
		<comments>http://www.winadmin.ro/2011/11/22/copy-files-between-servers-retaining-security-permissions/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 05:04:00 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[ACL]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/11/22/copy-files-between-servers-retaining-security-permissions/</guid>
		<description><![CDATA[Cu toate ca multi cred ca operatiunea din titlu e posibila doar folosind tool-uri de migrare gen FSMT, realitatea e ca operatiunea se poate efectua si de mana cu tool-urile builtin. De fapt cam tot ce face FSMT, un administrator priceput poate face si de mana. Secretul consta in cativa parametri ai comenzilor XCOPY si [...]]]></description>
			<content:encoded><![CDATA[<p>Cu toate ca multi cred ca operatiunea din titlu e posibila doar folosind tool-uri de migrare gen FSMT, realitatea e ca operatiunea se poate efectua si de mana cu tool-urile builtin. De fapt cam tot ce face FSMT, un administrator priceput poate face si de mana.</p>
<p>Secretul consta in cativa parametri ai comenzilor XCOPY si ROBOCOPY. Pe care dintre ele le folositi, depinde de alegerea fiecaruia pentru ca ambele stiu sa copieze ACL-urile fisierelor.</p>
<p>La XCOPY parametrul este /O:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/11/image11.png"><img style="margin: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; border: 0px;" src="http://www.winadmin.ro/wp-content/uploads/2011/11/image_thumb11.png" alt="image" width="644" height="321" border="0" /></a></p>
<p>Iar la ROBOCOPY este /SEC (bineinteles ca se poate si cu /COPYALL sau /COPY:DATS).</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/11/image12.png"><img style="margin: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; border: 0px;" src="http://www.winadmin.ro/wp-content/uploads/2011/11/image_thumb12.png" alt="image" width="573" height="484" border="0" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/11/image13.png"><img style="margin: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; border: 0px;" src="http://www.winadmin.ro/wp-content/uploads/2011/11/image_thumb13.png" alt="image" width="644" height="63" border="0" /></a></p>
<p>Spor!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/11/22/copy-files-between-servers-retaining-security-permissions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cum sa faci &#8220;replace&#8221; la permisiunile NTFS</title>
		<link>http://www.winadmin.ro/2011/04/18/cum-sa-faci-replace-la-permisiunile-ntfs/</link>
		<comments>http://www.winadmin.ro/2011/04/18/cum-sa-faci-replace-la-permisiunile-ntfs/#comments</comments>
		<pubDate>Sun, 17 Apr 2011 21:07:26 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[NTFS]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/04/18/cum-sa-faci-replace-la-permisiunile-ntfs/</guid>
		<description><![CDATA[Am stat cateva minute gandindu-ma la ce titlu sa pun. Poate si din cauza asta exista foarte putina informatie pe net despre acest subiect. Mai puteam sa-i spun ReACL sau ACL migration. Ca sa explic putin, o sa dau cateva exemple. 1. File Server in domeniul A. Trebuie sa migrez serverul in domeniul B si [...]]]></description>
			<content:encoded><![CDATA[<p>Am stat cateva minute gandindu-ma la ce titlu sa pun. Poate si din cauza asta exista foarte putina informatie pe net despre acest subiect. Mai puteam sa-i spun ReACL sau ACL migration.</p>
<p>Ca sa explic putin, o sa dau cateva exemple.</p>
<p>1. File Server in domeniul A. Trebuie sa migrez serverul in domeniul B si din anumite motive translatarea cu ADMT nu functioneaza.</p>
<p>2. File Server standalone (nu radeti ca am vazut si scenariul asta) ce urmeaza a fi migrat la domeniu. Permisiunile sunt date pe grupuri si useri locali si vreau sa le translatez la grupuri de domeniu (pe care cumva va trebui sa le mapez la grupurile locale pentru a nu pierde permisiunile).</p>
<p>3. File Server membru in domeniu dar cu permisiuni date pe grupuri locale, ca deh asa au inteles unii MCSE strategia <a href="http://www.winadmin.ro/2011/03/30/agdlpsau-despre-group-nesting-pe-windows/">AGDLP</a>.</p>
<p>Si scenariile mai pot continua dar e suficient deocamdata.</p>
<p>Pentru taskuri de genul asta ar cam fi cateva tool-uri:</p>
<p>- <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&amp;displaylang=en">Subinacl</a> – un tool foarte puternic dar in acelasi timp plin de bug-uri. In special pe partea de migrare de ACL-uri. Pentru alte taskuri merge chiar bine.</p>
<p>- <a href="http://helgeklein.com/">SetACL</a> – foarte interesant la prima vedere dar cu o sintaxa urata si cand vine vorba sa lucrezi cu anumite grupuri locale ii cam da cu virgula.</p>
<p>- <a href="http://technet.microsoft.com/en-us/library/cc758542(WS.10).aspx">Sidwalker tools</a> – campionul nostru la exercitiul de azi. Este cea mai buna varianta FREE pentru a translata permisiunile.</p>
<p>Are chiar si un MMC care arata cam asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image13.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb13.png" width="554" height="245" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image14.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb14.png" width="311" height="281" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image15.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb15.png" width="644" height="450" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image16.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb16.png" width="644" height="413" /></a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image17.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb17.png" width="419" height="348" /></a></p>
<p>Dupa ce am facut maparile din MMC putem exporta totul intr-un fisier de mapare:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image18.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb18.png" width="644" height="239" /></a></p>
<p>Cum interfata grafica este destul de primitiva si daca avem multe obiecte este imposibil de folosit, ne folosim de ea doar ca sa generam un model al fisierului de mapare. Din momentul acesta tot ce aveti de facut este sa generati fisierul in formatul de mai sus. Vbscript e util dar si mai util e sa stiti Excel (eu nu stiu, dar am pe cine sa intreb la nevoie). Atentie ca o sa aveti nevoie si de SID-urile obiectelor.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image19.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb19.png" width="644" height="321" /></a></p>
<p>Eu acum facand doar un test/demo o sa ma folosesc doar de ce am generat cu MMC-ul Sidwalker. Si tit ca test o sa iau un folder unde pun permisiuni pe doua grupuri locale&quot;.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image20.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb20.png" width="368" height="473" /></a></p>
<p>Rulam Sidwalker:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image21.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb21.png" width="644" height="390" /></a></p>
<p>O sa primim erori pentru fiecare entry in ACL caruia nu i-am mapat nimic – asta se datoreaza grupurilor Builtin dar care vreau sa ramana acolo neatinse.</p>
<p>Si iata si rezultatul:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/04/image22.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/04/image_thumb22.png" width="368" height="476" /></a></p>
<p>Sidwalker poate scana tot sistemul si translata ACL-urile de pe fisiere, share-uri, printere, registry, mai exact cu o singura comanda poti translata tot ce se afla pe acel sistem.</p>
<p>Tineti minte acest tool si rugati-va ca Microsoft sa nu-l uite si sa-l updateze.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/04/18/cum-sa-faci-replace-la-permisiunile-ntfs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting AD OUs from accidental deletion</title>
		<link>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/</link>
		<comments>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 12:59:11 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[Organizational Unit]]></category>
		<category><![CDATA[Permissions]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/</guid>
		<description><![CDATA[&#160; Incepand cu Windows 2008, in consola Active Directory Users and Computers exista o optiune care protejeaza OU-urile de la stergerea accidentala: Iata ce se intampla cand vrem sa-l stergem: Ca sa puteti sterge un OU, trebuie sa debifati&#160; “protect object from accidental deletion”. E bine gandita optiunea; am intalnit cazuri in care unii admini [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Incepand cu Windows 2008, in consola Active Directory Users and Computers exista o optiune care protejeaza OU-urile de la stergerea accidentala:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image51.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb43.png" width="439" height="484" /></a></p>
<p>Iata ce se intampla cand vrem sa-l stergem:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image52.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb44.png" width="644" height="453" /></a> </p>
<p>Ca sa puteti sterge un OU, trebuie sa debifati&#160; “protect object from accidental deletion”. E bine gandita optiunea; am intalnit cazuri in care unii admini au sters containere intregi cu toate obiectele din ele si a trebuit sa apelez la restore din backup.</p>
</p>
<p>&#160;</p>
<p>Dar ce facem daca folosim Windows 2003? Nici o problema, exista solutie si aici.</p>
<p>Setam Deny pe Delete si Delete Subtree in Advanced security settings.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image53.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb45.png" width="644" height="454" /></a> </p>
<p>Iar pe containerul parinte (in cazul meu e domain root) setam Deny pe Delete All Child Objects.</p>
<p align="left">&#160;</p>
<p align="left"><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image54.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb46.png" width="644" height="454" /></a></p>
<p align="left">Iata ce se intampla cand incercam sa stergem Organizational Unit-ul.</p>
<p align="left"><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image55.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb47.png" width="644" height="450" /></a></p>
<p align="left">Operatiunea afecteaza doar OU-ul Test_Delete, fara a afecta obiectele din el (inclusiv OU-uri) si recomand a fi setat pe containerele top level cu foarte multe obiecte.&#160; </p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

