Information
Changing the system's file and directory permissions allows the possibility of unauthorized and anonymous modification to the operating system and installed applications.
The default permissions are adequate when the Security Option 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled' (WN25-SO-000240).
Satisfies: SRG-OS-000312-GPOS-00122, SRG-OS-000312-GPOS-00123, SRG-OS-000312-GPOS-00124
Solution
Maintain the default permissions for the system drive's root directory and configure the Security Option 'Network access: Let Everyone permissions apply to anonymous users' to 'Disabled' (WN25-SO-000240).
Default Permissions
C:\
Type - 'Allow' for all
Inherited from - 'None' for all
Principal - Access - Applies to
SYSTEM - Full control - This folder, subfolders, and files
Administrators - Full control - This folder, subfolders, and files
Users - Read & execute - This folder, subfolders, and files
Users - Create folders/append data - This folder and subfolders
Users - Create files/write data - Subfolders only
CREATOR OWNER - Full Control - Subfolders and files only