01 · Starting point
Situation
Missing or contradictory permissions, faulty folder redirections and conflicting group policies impaired reliable access to resources.
Constraints
- Changes within an already established IT environment
- Short, clearly scoped engagement
- Internal system and operating details remain confidential
02 · Responsibility
My scope of responsibility
I analysed ACLs, user attributes, folder redirection and GPO processing, developed corrections and scripted the required access control.
- I identified missing, incorrect and conflicting ACLs.
- I analysed and corrected folder redirection and GPO conflicts.
03 · Technical work
Documented scope of work
Key decisions
Investigate permission, user attribute and policy processing as one connected access chain. Individual ACL fixes would not have held if attribute scripts, paths or group policies kept producing contradictory states.
- I developed scripts for access control based on user attributes.
04 · Technical context
Technology in use
ACL
ACL was part of the documented toolset in this Security & Recovery engagement.
Active Directory
Active Directory was part of the documented toolset in this Security & Recovery engagement.
Group Policy
Group Policy was part of the documented toolset in this Security & Recovery engagement.
Folder Redirection
Folder Redirection was part of the documented toolset in this Security & Recovery engagement.
Scripting
Scripting was part of the documented toolset in this Security & Recovery engagement.
05 · Factual basis
Evidence and limits
Access control, folder access and policy application gained a more consistent technical foundation.
- Role
- System Administrator
- Period
- January 2010 — March 2010
Lesson from the engagement
Access problems are solved for good when permissions, identity data and policy processing are viewed end to end.
Confidentiality note: Internal architecture and operating data of this engagement are not published.