Browse Source

docs: explain why a share root loses its inherited permissions over UNC

Written through its UNC path, the DACL of a share root can't re-inherit
from the parent folder on the server: Windows drops the inherited entries
of a DACL in the auto-inherit format and stores the others as explicit
copies. icacls and Set-Acl behave the same; a subfolder through the share
and the local path keep them (#67).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
pull/112/head
Raimund Andree 5 days ago
parent
commit
63b23ce365
  1. 11
      Docs/FAQ.md

11
Docs/FAQ.md

@ -29,6 +29,17 @@ which Explorer adds for a path on a file share, and the account must be
resolvable on the computer that runs the cmdlet. See
[Get-NTFSEffectiveAccess](Cmdlets/Get-NTFSEffectiveAccess.md).
## The root of a share loses its inherited permissions over UNC
When you change the permissions of the root folder of a share through its
UNC path, such as `\\server\share`, Windows can't reach the parent folder on
the server to inherit from. The root folder then loses its inherited
entries, or keeps them as explicit entries that no longer follow the parent
folder. `icacls` and `Set-Acl` behave the same way. Change the root folder
through its local path on the server, such as `D:\Shares\Data`, and use the
UNC path for the folders below the root. See
[#67](https://github.com/raandree/NTFSSecurity/issues/67).
## Get-ChildItem2 -Recurse runs in a loop through junctions
A junction can point to a folder above it. Use `-SkipMountPoints` and

Loading…
Cancel
Save