PERMISSIONSCOPE / WINDOWS ACCESS INTELLIGENCE

Access report

C:\PermissionScope-Demo

2026-01-01 10:00:00Z · Snapshot 11111111111111111111111111111111

Scope

Read-only observations. Decisions describe discretionary permissions for one selected Windows identity. ACL principals are not a complete list of people. Share projections are not proof of a remote logon. Integrity policy, encryption, file locks and administrative overrides are outside this decision.

Summary

5 objects observed · 0 read errors · 5 findings · Scan completed

Findings

CategoryPathEvidenceReview
ReviewC:\PermissionScope-Demo\FinanceInheritance is disabled on this object.Confirm this permission boundary is intentional.
ReviewC:\PermissionScope-Demo\ProjectsInheritance is disabled on this object.Confirm this permission boundary is intentional.
ReviewC:\PermissionScope-Demo\SharedInheritance is disabled on this object.Confirm this permission boundary is intentional.
ReviewC:\PermissionScope-Demo\PrivateInheritance is disabled on this object.Confirm this permission boundary is intentional.
Review\\LAB-FILESERVER\SharedInheritance is disabled on this object.Confirm this permission boundary is intentional.

Access for the selected identity

Path / identityDecisionNTFS / share projectionLimitations
C:\PermissionScope-Demo\Finance
LAB\Alex
Partial0x001301BF /
C:\PermissionScope-Demo\Projects
LAB\Alex
Granted0x001F01FF /
C:\PermissionScope-Demo\Shared
LAB\Alex
Partial0x00120089 /
C:\PermissionScope-Demo\Private
LAB\Alex
Denied0x00000000 /
\\LAB-FILESERVER\Shared
LAB\Alex
Unknown0x00120089 / 0x00120089Synthetic remote example: the server logon token is not established.

Why · Technical evidence

Synthetic demonstration: fictional identities, resources and permissions evaluated by Windows Authz. No machine inventory was collected.

C:\PermissionScope-Demo\Finance

Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.

PrincipalRelationMask / contributionSource
LAB\Finance
S-1-5-21-111111111-222222222-333333333-2001
GrantedBy · ACE 00x001301BF / 0x001301BFC:\PermissionScope-Demo\Finance
None
S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2001 [Synthetic fixture membership; supplied to Authz]

Security descriptor

O:SYG:SYD:P(A;;0x1301BF;;;S-1-5-21-111111111-222222222-333333333-2001)

SHA-256: 2BEDBF989CBAAB812F240DAC8934A23F8EEFFC96DDB49C63D38143AE3B4B69DA

C:\PermissionScope-Demo\Projects

Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.

PrincipalRelationMask / contributionSource
LAB\Employees
S-1-5-21-111111111-222222222-333333333-2002
GrantedBy · ACE 00x001F01FF / 0x001F01FFC:\PermissionScope-Demo\Projects
None
S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz]

Security descriptor

O:SYG:SYD:P(A;;FA;;;S-1-5-21-111111111-222222222-333333333-2002)

SHA-256: B846185AD1827E0A57888517A2994ACC2EE07A09606F810F2407745A030A5B64

C:\PermissionScope-Demo\Shared

Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.

PrincipalRelationMask / contributionSource
LAB\Employees
S-1-5-21-111111111-222222222-333333333-2002
GrantedBy · ACE 00x00120089 / 0x00120089C:\PermissionScope-Demo\Shared
None
S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz]

Security descriptor

O:SYG:SYD:P(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)

SHA-256: 9309201A68AC9D6D8BC095C9F0C2D68C2E1B2A1863824BE02E42EFDDD2C2253C

C:\PermissionScope-Demo\Private

Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.

PrincipalRelationMask / contributionSource
LAB\Alex
S-1-5-21-111111111-222222222-333333333-1001
DeniedBy · ACE 00x001F01FF / 0x001F01FFC:\PermissionScope-Demo\Private
None
LAB\Employees
S-1-5-21-111111111-222222222-333333333-2002
GrantedBy · ACE 10x00120089 / 0x00000000C:\PermissionScope-Demo\Private
None
S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz]

Security descriptor

O:SYG:SYD:P(D;;FA;;;S-1-5-21-111111111-222222222-333333333-1001)(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)

SHA-256: 54E6AC7ACCC9249CB4FF0C874F9B39032AB436F5DF3A53CD8310F557E0E88CD1

\\LAB-FILESERVER\Shared

Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.

PrincipalRelationMask / contributionSource
LAB\Employees
S-1-5-21-111111111-222222222-333333333-2002
GrantedBy · ACE 00x00120089 / 0x00120089\\LAB-FILESERVER\Shared
None
S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz]

Security descriptor

O:SYG:SYD:P(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)

SHA-256: 9309201A68AC9D6D8BC095C9F0C2D68C2E1B2A1863824BE02E42EFDDD2C2253C

Errors / unknowns