Stopping admin accounts accessing another's documents

yohan

New member
Local time
9:14 AM
Messages
23
Hi, I have two administrator accounts setup, but they can access each other's documents (C:\Users\Example). I tried removing all but the owner in the security tab, but administrators can take ownership this way somehow, anyone know what I can do (besides making them non-administrator accounts)
 

My Computer My Computer

At a glance

Windows 7 x64 build 7100Core 2 Duo E6550 @ 2.80GHz4GB HyperX 1066MHz @ 960MHz 5-5-5-15Nvidia (Zotac) 8800GT 512MB OC
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 build 7100
CPU
Core 2 Duo E6550 @ 2.80GHz
Motherboard
GA-P35-DS3P
Memory
4GB HyperX 1066MHz @ 960MHz 5-5-5-15
Graphics Card(s)
Nvidia (Zotac) 8800GT 512MB OC
Sound Card
Realtek HD on-board
Monitor(s) Displays
Samsung 2232BW
Screen Resolution
1680x1050
Hard Drives
640 GB WD 7200RPM
PSU
600w Hiper SLi PSU
Case
Antec 300
Cooling
Lots of 120+140+160mm fans..
Keyboard
MS Wired 500
Mouse
Razer Diamondback 3g
Internet Speed
ADSL2+ @ ~4 Mbps
Correct me if I am wrong (which I likely am) but wouldn't creating a password for those two admin accounts prevent them from accessing each other without the other ones password?
 

My Computer My Computer

At a glance

Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04Intel E6750 @ 3.80GHz2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHzEVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Computer Manufacturer/Model Number
Custom | Whitebox
OS
Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04
CPU
Intel E6750 @ 3.80GHz
Motherboard
Gigabyte GA-EP45-UD3L (Revision 1.1)
Memory
2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHz
Graphics Card(s)
EVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Sound Card
Realtek ALC888
Monitor(s) Displays
21" VIZIO TV
Screen Resolution
1680x1050 @ 60Hz
Hard Drives
Western Digital WD6401AALS - 640GB
Hitachi HDP725016GLA380 - 160GB
PSU
Corsair 750W
Case
NZXT Nemesis Elite
Cooling
Thermaltake SpinQ
Keyboard
Logitech Wireless S520
Mouse
Logitech Wireless S520 - Microsoft Wireless Arc Mouse
Internet Speed
Download: 20mbps, Upload: 3mbps
Hi, I have two administrator accounts setup, but they can access each other's documents (C:\Users\Example). I tried removing all but the owner in the security tab, but administrators can take ownership this way somehow, anyone know what I can do (besides making them non-administrator accounts)

Hi Yohan,

You can remove the Administrators Group from always being able to take ownership of objects via the Local Security Policy ;)

If you remove all users and groups from this setting then no one can universally take ownership of anything if they don't already have the permission for that file or folder ;)

Just to be safe leave at least one account or group here so they can always take ownership of any object encase you accidentally get locked out of your own files ;)

LocalSec.JPG

Hope it helps.

Steven

Correct me if I am wrong (which I likely am) but wouldn't creating a password for those two admin accounts prevent them from accessing each other without the other ones password?

Users in the administrative group can always take ownership of anything regardless of what user or permission they have set for that file or folder, it all depends on this local Sec policy setting as to what group has unrestricted security access ;)
 
No, users in the administrative group can always take ownershiop of anything on the system regardless of what user or permission they have set, it all depends on this local Sec policy setting ;)

Well at least I tried. That kind of defeats the purpose of a password doesn't it though?

Also.. OMG we have the same name! lol had to say it.
 

My Computer My Computer

At a glance

Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04Intel E6750 @ 3.80GHz2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHzEVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Computer Manufacturer/Model Number
Custom | Whitebox
OS
Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04
CPU
Intel E6750 @ 3.80GHz
Motherboard
Gigabyte GA-EP45-UD3L (Revision 1.1)
Memory
2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHz
Graphics Card(s)
EVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Sound Card
Realtek ALC888
Monitor(s) Displays
21" VIZIO TV
Screen Resolution
1680x1050 @ 60Hz
Hard Drives
Western Digital WD6401AALS - 640GB
Hitachi HDP725016GLA380 - 160GB
PSU
Corsair 750W
Case
NZXT Nemesis Elite
Cooling
Thermaltake SpinQ
Keyboard
Logitech Wireless S520
Mouse
Logitech Wireless S520 - Microsoft Wireless Arc Mouse
Internet Speed
Download: 20mbps, Upload: 3mbps
Well at least I tried. That kind of defeats the purpose of a password doesn't it though?

Also.. OMG we have the same name! lol had to say it.

Administrators are Administrators, they can just reset your password if they like (you can remove that privilege for admins via group policy too) ;)

Hope it helps Steven :p

Steven
 
Thanks for your help, but it seems after setting the "Policy take-owner ability" to user "Bob", user "Dave" can still access Bob's area, after giving UAC permission to do so. After he does this, in the share tab, Bob is still owner, but Dave is now there, and has "Read/Write" access. How can I stop this?

Thanks so far by the way Steven & Steven.
 

My Computer My Computer

At a glance

Windows 7 x64 build 7100Core 2 Duo E6550 @ 2.80GHz4GB HyperX 1066MHz @ 960MHz 5-5-5-15Nvidia (Zotac) 8800GT 512MB OC
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 build 7100
CPU
Core 2 Duo E6550 @ 2.80GHz
Motherboard
GA-P35-DS3P
Memory
4GB HyperX 1066MHz @ 960MHz 5-5-5-15
Graphics Card(s)
Nvidia (Zotac) 8800GT 512MB OC
Sound Card
Realtek HD on-board
Monitor(s) Displays
Samsung 2232BW
Screen Resolution
1680x1050
Hard Drives
640 GB WD 7200RPM
PSU
600w Hiper SLi PSU
Case
Antec 300
Cooling
Lots of 120+140+160mm fans..
Keyboard
MS Wired 500
Mouse
Razer Diamondback 3g
Internet Speed
ADSL2+ @ ~4 Mbps
The point of Administrators is to have full access. If you don't want full access, make each other power users.
 

My Computer My Computer

At a glance

Windows 7 RC (Build 7100)AMD Athlon XP 2400+1.25 GBATI Radeon
Computer Manufacturer/Model Number
Home-Built and has been slowly upgraded since 1999
OS
Windows 7 RC (Build 7100)
CPU
AMD Athlon XP 2400+
Motherboard
ECS L7S7A2
Memory
1.25 GB
Graphics Card(s)
ATI Radeon
Sound Card
SoundBlaster Live! Platinum (w/ Live! Drive)
Monitor(s) Displays
ViewSonic 19" LCD
Screen Resolution
1440x900
Hard Drives
320GB PATA
250GB external USB Backup
PSU
500W
Case
Generic Beige Box
Cooling
A bunch of Fans
Keyboard
Old one with the keys pried off that I don't use
Mouse
Microsoft Optical Mouse I found at Unclaimed baggage for $10
Internet Speed
Knology Cable Internet (~6-7Mbps)
The point of Administrators is to have full access. If you don't want full access, make each other power users.

Yes but an admin having the ability to spy on the other admin is stupid in my opinion.

=\
 

My Computer My Computer

At a glance

Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04Intel E6750 @ 3.80GHz2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHzEVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Computer Manufacturer/Model Number
Custom | Whitebox
OS
Windows 7 Ultimate, OS X 10.7, Ubuntu 11.04
CPU
Intel E6750 @ 3.80GHz
Motherboard
Gigabyte GA-EP45-UD3L (Revision 1.1)
Memory
2x2GB & 2x1GB (6GB) OCZ Reaper 1066MHz @ 1080MHz
Graphics Card(s)
EVGA nVidia GTX 260 896mb (216 Core) FTW Edition
Sound Card
Realtek ALC888
Monitor(s) Displays
21" VIZIO TV
Screen Resolution
1680x1050 @ 60Hz
Hard Drives
Western Digital WD6401AALS - 640GB
Hitachi HDP725016GLA380 - 160GB
PSU
Corsair 750W
Case
NZXT Nemesis Elite
Cooling
Thermaltake SpinQ
Keyboard
Logitech Wireless S520
Mouse
Logitech Wireless S520 - Microsoft Wireless Arc Mouse
Internet Speed
Download: 20mbps, Upload: 3mbps
The point of Administrators is to have full access. If you don't want full access, make each other power users.

I don't think Power Users exist anymore.

Edit:

I'm wrong.

This works.
 

My Computer My Computer

At a glance

Windows 7 x64 build 7100Core 2 Duo E6550 @ 2.80GHz4GB HyperX 1066MHz @ 960MHz 5-5-5-15Nvidia (Zotac) 8800GT 512MB OC
Computer Manufacturer/Model Number
Custom
OS
Windows 7 x64 build 7100
CPU
Core 2 Duo E6550 @ 2.80GHz
Motherboard
GA-P35-DS3P
Memory
4GB HyperX 1066MHz @ 960MHz 5-5-5-15
Graphics Card(s)
Nvidia (Zotac) 8800GT 512MB OC
Sound Card
Realtek HD on-board
Monitor(s) Displays
Samsung 2232BW
Screen Resolution
1680x1050
Hard Drives
640 GB WD 7200RPM
PSU
600w Hiper SLi PSU
Case
Antec 300
Cooling
Lots of 120+140+160mm fans..
Keyboard
MS Wired 500
Mouse
Razer Diamondback 3g
Internet Speed
ADSL2+ @ ~4 Mbps
You can remove the Administrators Group from always being able to take ownership of objects via the Local Security Policy ;)

That's a good trick, and funny, but if the other Admin is smart enough he can also edit the Local Security Policy.

I wonder if, besides using a Power User, there is a way to solve this using built-in encryption? I know EFS was a pretty weak system but have there been any improvements to this in Win7?
 

My Computer My Computer

At a glance

XP, Seven, 2008R2AMD, Intel, VIACorsair, Kingston, etc.ATI, NVIDIA
Computer Manufacturer/Model Number
Too many to list.
OS
XP, Seven, 2008R2
CPU
AMD, Intel, VIA
Motherboard
Various
Memory
Corsair, Kingston, etc.
Graphics Card(s)
ATI, NVIDIA
Monitor(s) Displays
Samsung
Hard Drives
Maxtor, Western Digital
Keyboard
qwerty
Internet Speed
22 Mb/s @ home, 1 Gb/s @ server
Other Info
All of my systems still run fastest on XP 32-bit for the most part. Win7 is fun to play with, but I still prefer XP for raw speed, security, and functionality.
That's a good trick, and funny, but if the other Admin is smart enough he can also edit the Local Security Policy.

If you take ownership of mmc.exe and gpedit.msc then set the security to prevent access, other admins would be unable to edit policy's ;)

I wonder if, besides using a Power User, there is a way to solve this using built-in encryption? I know EFS was a pretty weak system but have there been any improvements to this in Win7?

Unless an Admin configures a recovery key, other users cant access EFS protected files. I would keep regular backups of your EFS key encase your password is reset since it will also erase your EFS key as a security measure ;)

Steven
 
Unfortunately I don't think EFS will protect the files from being deleted, unless of course something has changed in Windows 7.
 

My Computer My Computer

At a glance

XP, Seven, 2008R2AMD, Intel, VIACorsair, Kingston, etc.ATI, NVIDIA
Computer Manufacturer/Model Number
Too many to list.
OS
XP, Seven, 2008R2
CPU
AMD, Intel, VIA
Motherboard
Various
Memory
Corsair, Kingston, etc.
Graphics Card(s)
ATI, NVIDIA
Monitor(s) Displays
Samsung
Hard Drives
Maxtor, Western Digital
Keyboard
qwerty
Internet Speed
22 Mb/s @ home, 1 Gb/s @ server
Other Info
All of my systems still run fastest on XP 32-bit for the most part. Win7 is fun to play with, but I still prefer XP for raw speed, security, and functionality.
One Caveat

Bear in mind that the folder you are trying to protect must have been created by the user who is trying to secure and own it; ie, if root creates it, then fred tries to secure it, he cannot.
 

My Computer My Computer

At a glance

Win 7 UltimateIntel dual core 2.4 ghz4 gigGeoforce
Computer Manufacturer/Model Number
ASUS P5NSLI
OS
Win 7 Ultimate
CPU
Intel dual core 2.4 ghz
Motherboard
ASUS P5NSLI
Memory
4 gig
Graphics Card(s)
Geoforce
Back
Top