May 8th, 2012

Why can't I use the file sharing wizard if I exclude inheritable permissions from a folder's parent?

In Windows Vista and Windows Server 2008, if you go to a the advanced security settings for a directory and uncheck “include inheritable permissions from this object’s parent”, then go back to the Sharing tab, you’ll find that the “Share” button is disabled. Why is this? We don’t see this behavior on Windows 7 or Windows Server 2008 R2. (Yes, a customer actually noticed and asked the question.) The sharing wizard in Windows Vista and Windows Server 2008 does not support folders with the SE_DACL_PROTECTED security descriptor control bit because it isn’t sure that it can restore the ACL afterward.

And as the customer noted, this restriction was lifted in Windows 7 and Windows Server 2008 R2.

Author

Raymond has been involved in the evolution of Windows for more than 30 years. In 2003, he began a Web site known as The Old New Thing which has grown in popularity far beyond his wildest imagination, a development which still gives him the heebie-jeebies. The Web site spawned a book, coincidentally also titled The Old New Thing (Addison Wesley 2007). He occasionally appears on the Windows Dev Docs Twitter account to tell stories which convey no useful information.

0 comments

Discussion are closed.