Jump to content

Security descriptor

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 221.128.180.161 (talk) at 17:41, 20 October 2007. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Security descriptors are structures pointing to security information for securable Windows objects, that is objects that can be identified by a unique name. Security descriptors can be associated with any named objects, including files, folders, registry keys and other resources, and contain information about the owner (creating user) of the object as well as which users can access the object, the type of access (read, read/write, execute, etc) on a per-user basis, among others.

It is possible to edit, using various tools like the Windows command line tool 'CACLS', the 'permissions' of files and folders for every user or group. (Of course, to do so, a given user must be an administrator and have the appropriate access to the object (file or folder) whose security descriptor is being altered.)

See Also