All lessons Leer en español

Security in depth · Unit 22 · Lesson 35 of 44

User rights differ from file permissions

Evaluate a system privilege separately from folder access and its present token state.

3 minreadyShort lesson

Helpful before thisWindows privilege escalation

See all lessons in this topic

After this lesson you can

  • Distinguish an assigned privilege, its state in a token, and the business need for it.

Look beyond the folder

A Windows privilege authorizes a class of system operations rather than ordinary access to one named file. User-rights policy also includes logon rights; not every user right is the same kind of privilege. This example concerns a privilege associated with changing system time.

Review three different facts: the account’s assignment, whether the privilege appears in the relevant token, and its current enabled or disabled state. An assigned privilege is not proof that a particular action succeeded. Conversely, a disabled state in one snapshot does not demonstrate that the account has permanently lost that authority.

Supplied support-role record

The fictional ReportSupport role only needs to read published summaries. Its owner confirms that clock administration belongs to the platform team. The policy record assigns ReportSupport the system-time privilege, while its current token lists that privilege as disabled. Ordinary report access is working.

Assume the records describe the same account and relevant token, with no other business requirement supplied. There is no evidence that the role changed the clock. The confirmed issue is an unexplained assignment beyond its stated duty, not an observed unauthorized operation.

Assigned right → Relevant token → System operationAssigned rightRelevant tokenSystem operation
Assignment, relevant token, and system operation are distinct evidence questions; an assignment alone does not prove use.

Define a proportionate review

Ask the policy owner why the assignment exists, which effective policy supplies it, and what legitimate workflow depends on it. A broad administrative group name alone is an incomplete inventory of authority. Acceptance should establish the intended narrower assignment in the applicable context and verify that report reading still works. Record any approved exception and its review date; do not treat file permissions as a substitute for examining system rights.

Terms you met

Privilege

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. A report-only role has a system-time privilege present but disabled in its current token. No approved clock-management duty exists. What is justified?

    Show the answer

    Correct answer: Review the unnecessary assignment; a disabled current state does not establish a lasting absence of authority. The role's business need and assigned privilege remain relevant beyond this one token snapshot.

Try it

  • WriteWrite a privilege-review record containing approved work, assigned authority, observed token state, owner, and the result needed to show routine work survives a narrower assignment.
References