Security in depth · Unit 22 · Lesson 35 of 44
User rights differ from file permissions
Evaluate a system privilege separately from folder access and its present token state.
Helpful before thisWindows privilege escalation
After this lesson you can
- Distinguish an assigned privilege, its state in a token, and the business need for it.
Look beyond the folder
A Windows privilege authorizes a class of system operations rather than ordinary access to one named file. User-rights policy also includes logon rights; not every user right is the same kind of privilege. This example concerns a privilege associated with changing system time.
Review three different facts: the account’s assignment, whether the privilege appears in the relevant token, and its current enabled or disabled state. An assigned privilege is not proof that a particular action succeeded. Conversely, a disabled state in one snapshot does not demonstrate that the account has permanently lost that authority.
Supplied support-role record
The fictional ReportSupport role only needs to read published summaries. Its owner confirms that clock administration belongs to the platform team. The policy record assigns ReportSupport the system-time privilege, while its current token lists that privilege as disabled. Ordinary report access is working.
Assume the records describe the same account and relevant token, with no other business requirement supplied. There is no evidence that the role changed the clock. The confirmed issue is an unexplained assignment beyond its stated duty, not an observed unauthorized operation.
Define a proportionate review
Ask the policy owner why the assignment exists, which effective policy supplies it, and what legitimate workflow depends on it. A broad administrative group name alone is an incomplete inventory of authority. Acceptance should establish the intended narrower assignment in the applicable context and verify that report reading still works. Record any approved exception and its review date; do not treat file permissions as a substitute for examining system rights.
Terms you met
Check yourself
No timer. No penalties. Read the explanation and try again whenever you like.
This lesson’s questions have changed. Your reading progress is saved; review the updated questions.
-
A report-only role has a system-time privilege present but disabled in its current token. No approved clock-management duty exists. What is justified?
Show the answer
Correct answer: Review the unnecessary assignment; a disabled current state does not establish a lasting absence of authority. The role's business need and assigned privilege remain relevant beyond this one token snapshot.
Try it
- WriteWrite a privilege-review record containing approved work, assigned authority, observed token state, owner, and the result needed to show routine work survives a narrower assignment.