Read-only observations. Decisions describe discretionary permissions for one selected Windows identity. ACL principals are not a complete list of people. Share projections are not proof of a remote logon. Integrity policy, encryption, file locks and administrative overrides are outside this decision.
5 objects observed · 0 read errors · 5 findings · Scan completed
| Category | Path | Evidence | Review |
|---|---|---|---|
| Review | C:\PermissionScope-Demo\Finance | Inheritance is disabled on this object. | Confirm this permission boundary is intentional. |
| Review | C:\PermissionScope-Demo\Projects | Inheritance is disabled on this object. | Confirm this permission boundary is intentional. |
| Review | C:\PermissionScope-Demo\Shared | Inheritance is disabled on this object. | Confirm this permission boundary is intentional. |
| Review | C:\PermissionScope-Demo\Private | Inheritance is disabled on this object. | Confirm this permission boundary is intentional. |
| Review | \\LAB-FILESERVER\Shared | Inheritance is disabled on this object. | Confirm this permission boundary is intentional. |
| Path / identity | Decision | NTFS / share projection | Limitations |
|---|---|---|---|
| C:\PermissionScope-Demo\Finance LAB\Alex | Partial | 0x001301BF / | |
| C:\PermissionScope-Demo\Projects LAB\Alex | Granted | 0x001F01FF / | |
| C:\PermissionScope-Demo\Shared LAB\Alex | Partial | 0x00120089 / | |
| C:\PermissionScope-Demo\Private LAB\Alex | Denied | 0x00000000 / | |
| \\LAB-FILESERVER\Shared LAB\Alex | Unknown | 0x00120089 / 0x00120089 | Synthetic remote example: the server logon token is not established. |
Synthetic demonstration: fictional identities, resources and permissions evaluated by Windows Authz. No machine inventory was collected.
Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.
| Principal | Relation | Mask / contribution | Source |
|---|---|---|---|
LAB\FinanceS-1-5-21-111111111-222222222-333333333-2001 | GrantedBy · ACE 0 | 0x001301BF / 0x001301BF | C:\PermissionScope-Demo\Finance None S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2001 [Synthetic fixture membership; supplied to Authz] |
O:SYG:SYD:P(A;;0x1301BF;;;S-1-5-21-111111111-222222222-333333333-2001)SHA-256: 2BEDBF989CBAAB812F240DAC8934A23F8EEFFC96DDB49C63D38143AE3B4B69DA
Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.
| Principal | Relation | Mask / contribution | Source |
|---|---|---|---|
LAB\EmployeesS-1-5-21-111111111-222222222-333333333-2002 | GrantedBy · ACE 0 | 0x001F01FF / 0x001F01FF | C:\PermissionScope-Demo\Projects None S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz] |
O:SYG:SYD:P(A;;FA;;;S-1-5-21-111111111-222222222-333333333-2002)SHA-256: B846185AD1827E0A57888517A2994ACC2EE07A09606F810F2407745A030A5B64
Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.
| Principal | Relation | Mask / contribution | Source |
|---|---|---|---|
LAB\EmployeesS-1-5-21-111111111-222222222-333333333-2002 | GrantedBy · ACE 0 | 0x00120089 / 0x00120089 | C:\PermissionScope-Demo\Shared None S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz] |
O:SYG:SYD:P(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)SHA-256: 9309201A68AC9D6D8BC095C9F0C2D68C2E1B2A1863824BE02E42EFDDD2C2253C
Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.
| Principal | Relation | Mask / contribution | Source |
|---|---|---|---|
LAB\AlexS-1-5-21-111111111-222222222-333333333-1001 | DeniedBy · ACE 0 | 0x001F01FF / 0x001F01FF | C:\PermissionScope-Demo\Private None |
LAB\EmployeesS-1-5-21-111111111-222222222-333333333-2002 | GrantedBy · ACE 1 | 0x00120089 / 0x00000000 | C:\PermissionScope-Demo\Private None S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz] |
O:SYG:SYD:P(D;;FA;;;S-1-5-21-111111111-222222222-333333333-1001)(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)SHA-256: 54E6AC7ACCC9249CB4FF0C874F9B39032AB436F5DF3A53CD8310F557E0E88CD1
Synthetic demonstration. Windows Authz evaluates supplied fixture SIDs and descriptors; this is not an actual user logon or file-open test.
| Principal | Relation | Mask / contribution | Source |
|---|---|---|---|
LAB\EmployeesS-1-5-21-111111111-222222222-333333333-2002 | GrantedBy · ACE 0 | 0x00120089 / 0x00120089 | \\LAB-FILESERVER\Shared None S-1-5-21-111111111-222222222-333333333-1001 → S-1-5-21-111111111-222222222-333333333-2002 [Synthetic fixture membership; supplied to Authz] |
O:SYG:SYD:P(A;;FR;;;S-1-5-21-111111111-222222222-333333333-2002)SHA-256: 9309201A68AC9D6D8BC095C9F0C2D68C2E1B2A1863824BE02E42EFDDD2C2253C