{"id":8140,"date":"2026-03-13T09:03:34","date_gmt":"2026-03-13T08:03:34","guid":{"rendered":"https:\/\/www.bayoosoft.com\/unkategorisiert\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/"},"modified":"2026-03-13T16:24:04","modified_gmt":"2026-03-13T15:24:04","slug":"when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions","status":"publish","type":"post","link":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/","title":{"rendered":"When the file server becomes a black box: Typical problems with NTFS permissions"},"content":{"rendered":"<div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-left:0px;--awb-padding-right-small:0px;--awb-margin-top:50px;--awb-margin-bottom-small:-50px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-margin-bottom-small:-20px;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-one\" style=\"--awb-text-color:var(--awb-color2);--awb-margin-top:-10px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:50px;\"><h1 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:50;line-height:var(--awb-typography1-line-height);\"><h1><strong>When the file server becomes a black box: Typical problems with NTFS permissions<\/strong><\/h1><\/h1><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:20px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-margin-bottom-small:-50px;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\" style=\"--awb-font-size:17px;--awb-margin-top:0px;\"><p>Anyone who has ever spent hours searching for the cause of a mysterious &#8220;Access Denied&#8221; knows that NTFS permissions are not technically witchcraft. But managing them over years, teams and system changes is. In many organizations, what starts out as a straightforward structure develops into a growing thicket of group relationships, interrupted inheritance paths and direct user assignments that hardly anyone can fully understand.<\/p>\n<p>In our blog post, we show you the problems that repeatedly arise in practice and why transparency about access control lists, group structures and effective authorizations is not an optional extra, but a must.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-center\" style=\"--awb-padding-right:-30px;--awb-overflow:hidden;--awb-bg-color:hsla(var(--awb-custom_color_1-h),var(--awb-custom_color_1-s),var(--awb-custom_color_1-l),calc(var(--awb-custom_color_1-a) - 15%));--awb-bg-color-hover:hsla(var(--awb-custom_color_1-h),var(--awb-custom_color_1-s),var(--awb-custom_color_1-l),calc(var(--awb-custom_color_1-a) - 15%));--awb-bg-size:cover;--awb-box-shadow:0px 5px 17px 0px rgba(0,0,0,0.4);;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-margin-top-small:56px;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\" data-scroll-devices=\"small-visibility,medium-visibility,large-visibility\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-margin-bottom:0px;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none\"><img decoding=\"async\" width=\"1500\" height=\"1000\" alt=\"BAYOOSOFT - DSGVO Richtlinie Checkliste\" title=\"BAYOOSOFT &#8211; DSGVO Richtlinie Checkliste\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste.jpg\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste.jpg\" class=\"lazyload img-responsive wp-image-7605\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%271500%27%20height%3D%271000%27%20viewBox%3D%270%200%201500%201000%27%3E%3Crect%20width%3D%271500%27%20height%3D%271000%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste-200x133.jpg 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste-400x267.jpg 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste-600x400.jpg 600w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste-800x533.jpg 800w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste-1200x800.jpg 1200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT-DSGVO-Richtlinie-Checkliste.jpg 1500w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 1500px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:20px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>Grown over the years: When Access Control Lists (ACLs) become archive history<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-font-size:17px;--awb-margin-top:0px;\"><p>File server permissions grow with the company, and that&#8217;s the problem. Every reorganization, every admin change, every ad-hoc ticket leaves its mark on the ACLs. After a few years, you will find dozens of Access Control Entries (ACEs) in folders that no one can say why they are there. Orphaned SIDs (Security Identifier), recognizable by entries such as &#8220;Unknown account (S-123-12345)&#8221;, are a typical symptom: a user account has been deleted, but the associated ACE has remained untouched in the ACL.<\/p>\n<p>This is not an isolated case. In practice, the lack of an overview of established authorization structures is one of the most common causes of subsequent problems with NTFS administration. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-3 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2>Determine effective authorizations: Three levels, one question, a lot of effort<\/h2>\n<h2><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-3 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:0px;\"><p>One of the most technically demanding tasks is determining the actual effective permissions of a user. Effective permissions do not simply result from what is written in the NTFS ACL, but from the interaction of NTFS permissions, share permissions and Active Directory security groups.<\/p>\n<p>The key principle here is that if NTFS and share permissions apply at the same time, the more restrictive combination always applies. If a user can only read at share level but write at NTFS level, read-only access still applies for network access. This sounds logical, but quickly becomes confusing as soon as several group levels come into play.<\/p>\n<p>This is exactly the case with nested AD groups. A user is a member of a project group, which is a member of a department group, which in turn is in a file server authorization group. What rights does this user have to which folder? This question can only be answered with Windows on-board tools such as the Explorer security tab or icacls with considerable manual effort. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-4 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>Direct user authorizations and the AGDLP problem<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-4 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:3px;--awb-margin-bottom:0px;\"><p>One of the most common mistakes when assigning authorizations: users are entered directly into the ACL instead of controlling access via groups. This saves time in the short term. In the long term, it creates the very orphaned SIDs and lack of transparency that make audits a nightmare.<\/p>\n<p>Microsoft recommends the so-called AGDLP principle for Windows environments: user accounts are included in global groups, these global groups become members of domain-local groups, and only these domain-local groups receive the actual authorizations at folder level. If this model is implemented consistently, a single change to a group structure is sufficient to adjust permissions for all affected users. Direct ACEs, on the other hand, require manual corrections to each individual folder. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-5 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>Broken Inheritance and the quiet chaos underneath<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-5 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:30px;\"><p>Inheritance is actually intended to simplify authorization management: Permissions are set on top-level folders and propagate downwards. This works well as long as the inheritance is not interrupted.<\/p>\n<p>However, broken inheritance on individual subfolders is frequently encountered in practice, often because an admin has quickly created an exception. The result: changes at higher levels no longer take effect, permissions deviate from the rest of the structure in individual places, and no one has a complete overview of which folders actually have their own explicit ACLs. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-7 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-center\" style=\"--awb-padding-right:-30px;--awb-overflow:hidden;--awb-bg-color:hsla(var(--awb-custom_color_1-h),var(--awb-custom_color_1-s),var(--awb-custom_color_1-l),calc(var(--awb-custom_color_1-a) - 15%));--awb-bg-color-hover:hsla(var(--awb-custom_color_1-h),var(--awb-custom_color_1-s),var(--awb-custom_color_1-l),calc(var(--awb-custom_color_1-a) - 15%));--awb-bg-size:cover;--awb-box-shadow:0px 5px 17px 0px rgba(0,0,0,0.4);;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:40px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\" data-scroll-devices=\"small-visibility,medium-visibility,large-visibility\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-2 hover-type-none\"><img decoding=\"async\" width=\"2049\" height=\"1152\" alt=\"BAYOOSOFT Themis - Management Software - ISMS &amp; QMS\" title=\"BAYOOSOFT Themis &#8211; Management Software &#8211; ISMS &amp; QMS\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS.jpg\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS.jpg\" class=\"lazyload img-responsive wp-image-3461\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%272049%27%20height%3D%271152%27%20viewBox%3D%270%200%202049%201152%27%3E%3Crect%20width%3D%272049%27%20height%3D%271152%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS-200x112.jpg 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS-400x225.jpg 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS-600x337.jpg 600w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS-800x450.jpg 800w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS-1200x675.jpg 1200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/07\/BAYOOSOFT-Themis-Management-Software-ISMS-QMS.jpg 2049w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 2049px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-8 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-6 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>Access Creep: Rights grow, nobody cleans up<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-6 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:30px;\"><p>Employees change departments, take on new projects, temporarily take on substitute roles. Authorizations are assigned for each of these situations. Which rarely happens: The old rights are withdrawn again.<\/p>\n<p>This insidious process is known as access creep or privilege creep. Over time, a user has significantly more access rights than their current role actually requires. This is not only a compliance problem, it is also a concrete security risk. In the event of an attack or an insider incident, these excess rights can be used to cause significantly more damage than necessary. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-9 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-7 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>Deny overwrites Allow, always<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-7 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:30px;\"><p>Explicit Deny ACEs are a frequently underestimated source of errors. They overwrite Allow rights, regardless of the level or group at which the Allow was granted. A user can be a member of several groups, one of which has a deny, without anyone having consciously planned this.<\/p>\n<p>This makes troubleshooting access problems particularly tedious. The classic helpdesk case: A user reports &#8220;Access Denied&#8221;. Possible causes are missing NTFS read permissions, an overly restrictive share permission, a missing group membership, an interrupted inheritance or a deny ACE somewhere in the chain. This is almost impossible to analyze systematically with on-board tools. <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-10 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-8 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>What on-board equipment can and cannot do<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-8 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:30px;\"><p>Tools such as the Windows Explorer Security Tab, icacls or PowerShell allow ACLs to be queried. However, they do not provide a structured overview of a large file server with hundreds of folders and nested groups. Group dependencies can hardly be traced, effective authorizations have to be determined manually, and reporting or documentation are simply not scalable with on-board tools.<\/p>\n<p>Especially in audit or security situations, when the question is &#8220;Who currently has access to this folder?&#8221;, many administrators are faced with a real problem.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-11 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:30px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-9 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:40px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>What really helps: Transparency about ACL structures<\/strong><\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-9 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-margin-top:0px;--awb-margin-bottom:30px;\"><p>All of these problems have a common denominator: A lack of transparency. If you cannot see what is actually in your ACLs, which groups are nested and what effective rights a user really has, you cannot make targeted corrections.<\/p>\n<p>Specialized analysis tools for NTFS permissions start right here. The BAYOOSOFT NTFS Permission Analyzer gives administrators a structured overview of ACL structures, group relationships and effective access rights without having to open each folder manually. For a more comprehensive permission analysis and the ongoing management of access rights, the <b>BAYOOSOFT Access Manager<\/b> also offers a complete permission concept including recertification and lifecycle management.<\/p>\n<p>Are you unsure about your authorization situation? We will be happy to help you get an overview and give you tips on how to optimize your structures.<\/p>\n<\/div><div ><a class=\"fusion-button button-flat fusion-button-default-size button-default fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" target=\"_self\" href=\"www.bayoosoft.com\/en\/service-en\/permission-analysis-as-a-service\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Learn more<\/span><\/a><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-12 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-top:30px;--awb-padding-right:60px;--awb-padding-bottom:30px;--awb-padding-left:60px;--awb-overflow:hidden;--awb-bg-color:var(--awb-color1);--awb-bg-color-hover:var(--awb-color1);--awb-bg-size:cover;--awb-box-shadow:0px 5px 17px 0px rgba(0,0,0,0.4);;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:100%;--awb-margin-top-large:20px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:60px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-builder-row fusion-builder-row-inner fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"--awb-flex-grow:0;--awb-flex-grow-medium:0;--awb-flex-grow-small:0;--awb-flex-shrink:0;--awb-flex-shrink-medium:0;--awb-flex-shrink-small:0;width:104% !important;max-width:104% !important;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-0 fusion_builder_column_inner_2_3 2_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-text fusion-text-10 sm-text-align-center\" style=\"--awb-content-alignment:left;--awb-font-size:18px;--awb-line-height:var(--awb-typography2-line-height);--awb-letter-spacing:var(--awb-typography2-letter-spacing);--awb-text-transform:var(--awb-typography2-text-transform);--awb-text-color:var(--awb-custom_color_1);--awb-text-font-family:var(--awb-typography2-font-family);--awb-text-font-weight:var(--awb-typography2-font-weight);--awb-text-font-style:var(--awb-typography2-font-style);\"><p>This is how we support you<\/p>\n<\/div><div class=\"fusion-text fusion-text-11 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-text-color:var(--awb-color8);--awb-margin-bottom:25px;\"><p>Your solution around file servers, SharePoint, Active Directory and third-party systems \u2013 From standardizing user and access management to supporting the supply of IT services: Optimize entire process chains with BAYOOSOFT Access Manager and sustainably reduce operational efforts while increasing information security.<\/p>\n<\/div><div ><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-2 fusion-button-default-span fusion-button-default-type\" style=\"--button_accent_color:var(--awb-color1);--button_accent_hover_color:var(--awb-color1);--button_border_hover_color:var(--awb-color7);--button_border_width-top:1px;--button_border_width-right:1px;--button_border_width-bottom:1px;--button_border_width-left:1px;--button_gradient_top_color:var(--awb-color3);--button_gradient_bottom_color:var(--awb-color3);--button_gradient_top_color_hover:var(--awb-color7);--button_gradient_bottom_color_hover:var(--awb-color7);\" target=\"_self\" href=\"https:\/\/www.bayoosoft.com\/en\/product\/bayoosoft-access-manager\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Learn more<\/span><\/a><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-1 fusion_builder_column_inner_1_3 1_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio:1 \/ 1;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-3 hover-type-none has-aspect-ratio\"><img decoding=\"async\" width=\"300\" height=\"300\" title=\"BAYOOSOFT Access Manager\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager.png\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-300x300.png\" class=\"lazyload img-responsive wp-image-1226 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" alt srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27512%27%20height%3D%27512%27%20viewBox%3D%270%200%20512%20512%27%3E%3Crect%20width%3D%27512%27%20height%3D%27512%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-200x200.png 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-400x400.png 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager.png 512w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-13 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-10 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-text-color:var(--awb-color3);--awb-margin-top:0px;--awb-margin-bottom:0px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:var(--awb-typography2-font-size);\"><h2 class=\"fusion-title-heading title-heading-left sm-text-align-center fusion-responsive-typography-calculated\" style=\"margin:0;letter-spacing:-1px;font-size:1em;--fontSize:30;line-height:var(--awb-typography2-line-height);\"><h2><strong>FAQ: Frequently asked questions about NTFS permissions<\/strong><\/h2><\/h2><\/div><div class=\"accordian fusion-accordian\" style=\"--awb-border-size:0px;--awb-icon-size:30px;--awb-content-font-size:var(--awb-typography4-font-size);--awb-icon-alignment:left;--awb-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-border-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-background-color:var(--awb-color1);--awb-divider-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-divider-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-icon-color:var(--awb-color2);--awb-title-color:var(--awb-color8);--awb-content-color:var(--awb-color8);--awb-icon-box-color:var(--awb-color7);--awb-toggle-hover-accent-color:var(--awb-color7);--awb-title-font-family:&quot;Rubik&quot;;--awb-title-font-weight:500;--awb-title-font-style:normal;--awb-title-font-size:13pt;--awb-content-font-family:var(--awb-typography4-font-family);--awb-content-font-weight:var(--awb-typography4-font-weight);--awb-content-font-style:var(--awb-typography4-font-style);\"><div class=\"panel-group fusion-toggle-icon-unboxed\" id=\"accordion-8140-1\"><div class=\"fusion-panel panel-default panel-c0ea79572781be882 fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_c0ea79572781be882\"><a aria-expanded=\"false\" aria-controls=\"c0ea79572781be882\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#c0ea79572781be882\" href=\"#c0ea79572781be882\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What are effective permissions for NTFS?<\/span><\/a><\/div><\/div><div id=\"c0ea79572781be882\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_c0ea79572781be882\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Effective permissions are the actual effective access rights of a user to a folder or file. They result from the combination of NTFS permissions, share permissions and all group permissions in which the user is a member. The following applies: If NTFS and share permissions interact, the more restrictive variant always prevails. Deny ACEs always overwrite Allow permissions, regardless of the source.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-6adb88234dbd88840 fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_6adb88234dbd88840\"><a aria-expanded=\"false\" aria-controls=\"6adb88234dbd88840\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#6adb88234dbd88840\" href=\"#6adb88234dbd88840\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What is Access Creep and why is it a security risk?<\/span><\/a><\/div><\/div><div id=\"6adb88234dbd88840\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_6adb88234dbd88840\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Access creep (also known as privilege creep) refers to the gradual accumulation of access rights that users have accumulated through role changes, projects or substitutions and that have never been revoked. As unneeded rights remain in place, the potential attack surface in the event of cyber attacks or insider incidents increases considerably. Regular recertification of group memberships is the most effective countermeasure.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-a1040d6084dd3ae76 fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_a1040d6084dd3ae76\"><a aria-expanded=\"false\" aria-controls=\"a1040d6084dd3ae76\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#a1040d6084dd3ae76\" href=\"#a1040d6084dd3ae76\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What does Broken Inheritance mean with NTFS?<\/span><\/a><\/div><\/div><div id=\"a1040d6084dd3ae76\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_a1040d6084dd3ae76\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Broken inheritance means that the automatic inheritance of permissions from the parent folder to a specific subfolder has been deactivated. This folder then has its own explicit ACL, which is independent of changes at higher levels. This is sometimes intentional, but without careful documentation it quickly leads to inconsistent and difficult-to-understand authorization structures.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-2eb6dd4dbc625c5a1 fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_2eb6dd4dbc625c5a1\"><a aria-expanded=\"false\" aria-controls=\"2eb6dd4dbc625c5a1\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#2eb6dd4dbc625c5a1\" href=\"#2eb6dd4dbc625c5a1\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Why should users not be entered directly in ACLs?<\/span><\/a><\/div><\/div><div id=\"2eb6dd4dbc625c5a1\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_2eb6dd4dbc625c5a1\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Direct user authorizations in ACLs create a lack of transparency, as a user&#8217;s access rights cannot be read from their group membership. If the user account is deleted, an orphaned SID also remains in the ACL. Microsoft recommends the AGDLP principle instead: access rights are assigned to groups, users are authorized via group memberships.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-02a571778870a4d4a fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_02a571778870a4d4a\"><a aria-expanded=\"false\" aria-controls=\"02a571778870a4d4a\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#02a571778870a4d4a\" href=\"#02a571778870a4d4a\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Why are Deny ACEs so problematic?<\/span><\/a><\/div><\/div><div id=\"02a571778870a4d4a\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_02a571778870a4d4a\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Explicit Deny ACEs always take precedence over Allow rights in Windows, regardless of the level or group at which the Allow was granted. They can have an effect via group relationships without the entry causing them being immediately visible. This makes them the most common hidden cause of access blocks that are difficult to explain.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-ff1d11fb0fa63307f fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_ff1d11fb0fa63307f\"><a aria-expanded=\"false\" aria-controls=\"ff1d11fb0fa63307f\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#ff1d11fb0fa63307f\" href=\"#ff1d11fb0fa63307f\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What is the AGDLP principle?<\/span><\/a><\/div><\/div><div id=\"ff1d11fb0fa63307f\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_ff1d11fb0fa63307f\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>AGDLP stands for Accounts in Global groups, Global groups in Domain Local groups, Domain Local groups receive Permissions. It is Microsoft&#8217;s recommendation for scalable, role-based authorization assignment in Windows environments. If AGDLP is implemented consistently, authorizations can be controlled via a single group change instead of having to manually adjust hundreds of ACEs.<\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-2227067e23d9e5fe2 fusion-toggle-no-divider fusion-toggle-boxed-mode\" style=\"--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color7);\"><div class=\"panel-heading\"><div class=\"panel-title toggle\" id=\"toggle_2227067e23d9e5fe2\"><a aria-expanded=\"false\" aria-controls=\"2227067e23d9e5fe2\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8140-1\" data-target=\"#2227067e23d9e5fe2\" href=\"#2227067e23d9e5fe2\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What Windows on-board tools are available for analyzing NTFS permissions?<\/span><\/a><\/div><\/div><div id=\"2227067e23d9e5fe2\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_2227067e23d9e5fe2\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>The Security tab in Windows Explorer, the icacls command line tool and PowerShell cmdlets such as Get-Acl and Get-NTFSAccess (from the NTFS Security module) are available for analyzing ACLs. These tools provide useful information for individual folders, but quickly reach their limits when it comes to structured analysis of large file servers with many folders and nested groups: Group dependencies, effective rights and reporting can hardly be mapped in a scalable way.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":52,"featured_media":7996,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45,47],"tags":[125,104,103,85],"class_list":["post-8140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bayoosoft-access-manager-en","category-posts","tag-access-management","tag-access-manager","tag-iam","tag-management-system"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.6 (Yoast SEO v27.7) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Typical problems with NTFS permissions<\/title>\n<meta name=\"description\" content=\"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"When the file server becomes a black box: Typical problems with NTFS permissions\" \/>\n<meta property=\"og:description\" content=\"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/\" \/>\n<meta property=\"og:site_name\" content=\"BAYOOSOFT\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-13T08:03:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-13T15:24:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1333\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"lucyjordan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"lucyjordan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/\"},\"author\":{\"name\":\"lucyjordan\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/fafe2d1917d12370fc74ba58965208f8\"},\"headline\":\"When the file server becomes a black box: Typical problems with NTFS permissions\",\"datePublished\":\"2026-03-13T08:03:34+00:00\",\"dateModified\":\"2026-03-13T15:24:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/\"},\"wordCount\":8776,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/02\\\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg\",\"keywords\":[\"access management\",\"access manager\",\"iam\",\"management system\"],\"articleSection\":[\"BAYOOSOFT Access Manager\",\"Posts\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/\",\"name\":\"Typical problems with NTFS permissions\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/02\\\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg\",\"datePublished\":\"2026-03-13T08:03:34+00:00\",\"dateModified\":\"2026-03-13T15:24:04+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/fafe2d1917d12370fc74ba58965208f8\"},\"description\":\"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/02\\\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/02\\\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg\",\"width\":2000,\"height\":1333},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/www.bayoosoft.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"When the file server becomes a black box: Typical problems with NTFS permissions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/\",\"name\":\"BAYOOSOFT\",\"description\":\"L\u00f6sungen im Bereich IT-Security und Medical Solutions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.bayoosoft.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/fafe2d1917d12370fc74ba58965208f8\",\"name\":\"lucyjordan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g\",\"caption\":\"lucyjordan\"},\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Typical problems with NTFS permissions","description":"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/","og_locale":"en_US","og_type":"article","og_title":"When the file server becomes a black box: Typical problems with NTFS permissions","og_description":"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box","og_url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/","og_site_name":"BAYOOSOFT","article_published_time":"2026-03-13T08:03:34+00:00","article_modified_time":"2026-03-13T15:24:04+00:00","og_image":[{"width":2000,"height":1333,"url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg","type":"image\/jpeg"}],"author":"lucyjordan","twitter_card":"summary_large_image","twitter_misc":{"Written by":"lucyjordan","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#article","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/"},"author":{"name":"lucyjordan","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/fafe2d1917d12370fc74ba58965208f8"},"headline":"When the file server becomes a black box: Typical problems with NTFS permissions","datePublished":"2026-03-13T08:03:34+00:00","dateModified":"2026-03-13T15:24:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/"},"wordCount":8776,"commentCount":0,"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg","keywords":["access management","access manager","iam","management system"],"articleSection":["BAYOOSOFT Access Manager","Posts"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/","url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/","name":"Typical problems with NTFS permissions","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#primaryimage"},"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg","datePublished":"2026-03-13T08:03:34+00:00","dateModified":"2026-03-13T15:24:04+00:00","author":{"@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/fafe2d1917d12370fc74ba58965208f8"},"description":"When no one knows who has access: The most common problems with NTFS permissions and why file servers quickly become a black box","breadcrumb":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#primaryimage","url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg","contentUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/02\/BAYOOSOFT_Blog-IDM-und-DAG-2.jpg","width":2000,"height":1333},{"@type":"BreadcrumbList","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/when-the-file-server-becomes-a-black-box-typical-problems-with-ntfs-permissions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.bayoosoft.com\/"},{"@type":"ListItem","position":2,"name":"When the file server becomes a black box: Typical problems with NTFS permissions"}]},{"@type":"WebSite","@id":"https:\/\/www.bayoosoft.com\/#website","url":"https:\/\/www.bayoosoft.com\/","name":"BAYOOSOFT","description":"L\u00f6sungen im Bereich IT-Security und Medical Solutions","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bayoosoft.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/fafe2d1917d12370fc74ba58965208f8","name":"lucyjordan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7e1761cd577fb7c6b291dea96cc48fb7c214dad1036e7d35c964ecf253f36840?s=96&d=mm&r=g","caption":"lucyjordan"},"url":"https:\/\/www.bayoosoft.com\/en"}]}},"_links":{"self":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/users\/52"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/comments?post=8140"}],"version-history":[{"count":7,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8140\/revisions"}],"predecessor-version":[{"id":8220,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8140\/revisions\/8220"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media\/7996"}],"wp:attachment":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media?parent=8140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/categories?post=8140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/tags?post=8140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}