Updated ACL model in Vista improves on XP and 2003
June 5, 2007
There are various changes to the ACL model from XP/2003 to Windows Vista. Some are simple changes to defaults such as who has permission to create and modify files in the root of the boot volume, others are more complex regarding implicit permissions granted to the owner of an object and how this can be controlled even further.
Jesper Johansson has written an excellent and detailed Technet magazine article about Vista’s new ACL features and how these improve security. Some of this is just “useful to know” but effectively just gets on with the job under the hood; other parts are more useful to understand in depth to leverage the new capabilities.