Common System folder permissions
In the
Explorer
configure permissions to control whether a user-computer pair can view and change:- Product and system policies.
- Computer accounts and computer group accounts.
- Networks and devices.
- User accounts and user group accounts.To do thisFor this itemSecure this actionPrevent all access to the System folder and its contentsSystem folderReadDenyingReadaccess doesnotprevent users from reading tag values for devices in the Networks and Devices tree.Prevent users from modifying the properties of all items in the System folderSystem folderWrite
- DenyingWritealso prevents deleting user and group accounts if the accounts have group memberships associated with them. This is because group memberships are updated automatically when an account is deleted, and updating group memberships is controlled by the Write action.
- DenyingWriteaccess does not prevent users from writing tag values to devices in the Networks and Devices tree.
Prevent users from changing access to items in the System folder, but allow users to view and modify items in the System folderSystem folderConfigure SecurityAllow users to see the System folder, but none of the folders within itSystem folderList ChildrenPrevent users from deleting anything in the System folderSystem folderDeleteSecuring user and computer accountsAllow users to only view user and computer accounts, but prevent users from modifying or deleting themComputers and Groups;Users and GroupsAllowRead, andList Children;DenyWrite,Configure Security, andDeleteAllow users to create or delete user and computer accounts, but prevent users from locking other users out of the System folderSystem folderDenyConfigure Security;AllowRead, Write, List Children, andDeleteSecuring policy settingsPrevent users from viewing or changing policy settingsPolicies folderReadAllow users to view policy settings, but prevent users from changing policy settingsPolicies folderAllowReadandList Children;DenyWrite, andDeleteSecuring logical names for Networks and DevicesPrevent users from viewing Networks and DevicesNetworks and DevicesReadAllow users to view logical names but prevent users from modifying themNetworks and DevicesAllowReadandList Children;DenyWrite
Provide Feedback