Knowledge Base

How to specify access control on Window NT, Windows 2000, and Windows XP container objects

Article ID: 188760

Article Last Modified on 10/30/2006


APPLIES TO


This article was previously published under Q188760

SUMMARY

Programmatically specifying access control for Windows NT container objects is more complex than for other Win32 objects. This is because access control on container objects allows you to specify access to the container and access for objects that will be created in the container in the future.

MORE INFORMATION

A Windows NT securable object is a container if it can logically contain other securable objects. The following table shows the relationship between a container object and the objects it might contain:
   Container Object         Objects Contained
   -----------------------------------------------

   Directory                Files/Directories

   Registry Key             Registry Subkeys

   Windowstation            Desktop

   Printer                  Print Jobs
				
Windows NT, Windows 2000, and Windows XP support Access Control List (ACL) inheritance. This means that when a new object is created within a container object, the new object inherits permissions (access control entries marked as inheritable) from the parent container object by default.

When you programmatically assign access control to container objects, you must explicitly set the inheritance attribute of each access control entry (ACE). Use the following flags to set the ACE inheritance properties:
  • CONTAINER_INHERIT_ACE - Child objects that are containers, such as directories, inherit the ACE as an effective ACE.
  • OBJECT_INHERIT_ACE - Noncontainer child objects, such as files, inherit the ACE as an effective ACE.
  • INHERIT_ONLY_ACE - The ACE does not apply to the object to which it is attached but can be inherited by child objects.
For a complete description of these and the other possible AceFlags values, see the Win32 Platform SDK documentation for the ACE_HEADER structure.

There are two ways to assign inheritance flags to an access control entry, described below. Both require familiarity with access control. For additional information, see the Win32 Platform SDK and the following article in the Microsoft Knowledge Base:

102102 How To Add an Access-Allowed ACE to a File


Additional query words: directory sid special security printer

Keywords: kbhowto kbapi kbkernbase kbsecurity kbacl KB188760