<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Steve Riley on Security : access control</title><link>http://blogs.technet.com/steriley/archive/tags/access+control/default.aspx</link><description>Tags: access control</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Do you need RMS/IRM in Office for Macintosh?</title><link>http://blogs.technet.com/steriley/archive/2008/04/23/do-you-need-rms-irm-in-office-for-macintosh.aspx</link><pubDate>Thu, 24 Apr 2008 01:34:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3043863</guid><dc:creator>Steve Riley</dc:creator><slash:comments>19</slash:comments><comments>http://blogs.technet.com/steriley/comments/3043863.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=3043863</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=3043863</wfw:comment><description>&lt;p&gt;Please let me know if this is a feature you'd be interested in. We're looking to build the business case to develop it, and the best way to do that is for you, our customers, to let us know.&lt;/p&gt;  &lt;p&gt;Also, if any of you want to deploy RMS now but can't because there's currently no Mac support, I especially need to know. Thanks!&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3043863" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/RMS/default.aspx">RMS</category><category domain="http://blogs.technet.com/steriley/archive/tags/encryption/default.aspx">encryption</category><category domain="http://blogs.technet.com/steriley/archive/tags/access+control/default.aspx">access control</category></item><item><title>Plan now to eliminate "power users" from your domains</title><link>http://blogs.technet.com/steriley/archive/2008/02/11/plan-now-to-eliminate-power-users-from-your-domains.aspx</link><pubDate>Mon, 11 Feb 2008 21:03:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2870532</guid><dc:creator>Steve Riley</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/steriley/comments/2870532.aspx</comments><wfw:commentRss>http://blogs.technet.com/steriley/commentrss.aspx?PostID=2870532</wfw:commentRss><wfw:comment>http://blogs.technet.com/steriley/rsscomments.aspx?PostID=2870532</wfw:comment><description>&lt;p&gt;I've seen some conversations lately about the Power Users group -- how powerful is it, really, and why did we remove the group from Windows Vista?&lt;/p&gt; &lt;p&gt;That group had rights install software and drivers. And if you can install software and drivers, then you can elevate yourself to Administrator or SYSTEM. Vista includes a signed installer that allows standard users to install packages signed by a trusted root. (The "Trusted Installer" is a service that has a SID, so you'll see it in the permissions list on various objects throughout the operating system.) The installer validates the signature chain, then elevates itself to perform the actual installation. Now, standard users can install and update approved software without having to grant membership in the too-powerful Power Users group.&lt;/p&gt; &lt;p&gt;We deprecated the Power Users group and removed it wherever we detected it on ACLs. We recommend that you do the same.&lt;/p&gt; &lt;p&gt;More details in these blog postings:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://blogs.technet.com/jesper_johansson/archive/2006/03/12/421870.aspx" target="_blank"&gt;Power Users are Admins who have not made themselves Admin yet, by Jesper Johannson&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://blogs.technet.com/markrussinovich/archive/2006/05/01/the-power-in-power-users.aspx" target="_blank"&gt;The power in Power Users, by Mark Russinovich&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2870532" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/steriley/archive/tags/Windows+Vista/default.aspx">Windows Vista</category><category domain="http://blogs.technet.com/steriley/archive/tags/authentication/default.aspx">authentication</category><category domain="http://blogs.technet.com/steriley/archive/tags/security+policies/default.aspx">security policies</category><category domain="http://blogs.technet.com/steriley/archive/tags/access+control/default.aspx">access control</category></item></channel></rss>