<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Null and Empty DACLs</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx</link><description>Background 
 Mike here. Windows uses the concept of a security descriptor to allow or deny security principals (user or groups) access to specific resources. A security descriptor is a data structure that contains: 
 
 The memory location of a security</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>What occurs when the Security Group Policy CSE encounters a null DACL</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx#3249348</link><pubDate>Tue, 02 Jun 2009 17:03:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3249348</guid><dc:creator>Ask the Directory Services Team</dc:creator><description>&lt;p&gt;The Group Policy security client side extension can distribute security descriptors on files and registry&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3249348" width="1" height="1"&gt;</description></item><item><title>re: Null and Empty DACLs</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx#3249299</link><pubDate>Tue, 02 Jun 2009 15:16:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3249299</guid><dc:creator>MikeStephensMSFT</dc:creator><description>&lt;p&gt;Hello jlupolt,&lt;/p&gt;
&lt;p&gt;Unfortunately, the ACL editor within Windows shows the interpreted permission of the null or empty DACL. The command line utility cacls.exe does report a null DACL by displaying &amp;quot;No permissions are set.&amp;quot; I have an upcoming post that includes a script that specifically looks for null DACLs within nested folders.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3249299" width="1" height="1"&gt;</description></item><item><title>re: Null and Empty DACLs</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx#3249257</link><pubDate>Tue, 02 Jun 2009 12:30:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3249257</guid><dc:creator>HelgeKlein</dc:creator><description>&lt;p&gt;Thanks for the article Mike.&lt;/p&gt;
&lt;p&gt;If you want to detect NULL vs. empty ACLs you can use my open source tool SetACL (&lt;a rel="nofollow" target="_new" href="http://setacl.sourceforge.net/"&gt;http://setacl.sourceforge.net/&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;You might also be interested in my &amp;quot;primer&amp;quot; article on Windows permissions where I also explain the differences between NULL and empty ACLs:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.sepago.de/helge/2009/03/12/permissions-a-primer-or-dacl-sacl-owner-sid-and-ace-explained/"&gt;http://blogs.sepago.de/helge/2009/03/12/permissions-a-primer-or-dacl-sacl-owner-sid-and-ace-explained/&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3249257" width="1" height="1"&gt;</description></item><item><title>re: Null and Empty DACLs</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx#3248968</link><pubDate>Mon, 01 Jun 2009 22:41:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3248968</guid><dc:creator>jlupolt</dc:creator><description>&lt;p&gt;Thanks for this. How can a sysadmin tell the difference between an object with a null DACL and an object with an empty DACL? Would the permissions look the same if viewed in Explorer?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3248968" width="1" height="1"&gt;</description></item><item><title>  Ask the Directory Services Team : Null and Empty DACLs</title><link>http://blogs.technet.com/b/askds/archive/2009/06/01/null-and-empty-dacls.aspx#3248933</link><pubDate>Mon, 01 Jun 2009 21:34:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3248933</guid><dc:creator>  Ask the Directory Services Team : Null and Empty DACLs</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.tscmpro.com/?p=4246"&gt;http://www.tscmpro.com/?p=4246&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3248933" width="1" height="1"&gt;</description></item></channel></rss>