Chat now with support
Chat with Support

NOTICE! We are upgrading our support telephone services, implementing Genesys, starting the week of May 19, 2025

KACE Desktop Authority 11.3 - Installation and Upgrade Guide

File/Registry Permissions (User Management)

File/Registry Permissions

The File/Registry Permissions object provides the ability to modify NTFS File and Folder permissions or Registry permissions. Permissions are configurable for 2008, 7, 8.1,10, 2008 R2, 2012, 2012 R2, 2016, and 2019 systems only.

Settings

Action
Type

Select File/Folder or Registry from the Type list. The selected Type is the object that Permissions will be applied to.

Action

Select Append, Overwrite or Revoke from the Action list. This action defines how to apply the Permissions to the selected object.

  • Append - Add permissions to list of existing permissions for the object.
  • Overwrite - Replace existing permissions with permissions specified in this element for the object.
  • Revoke - Remove permissions for the object from the specified user/group.
Path/hive/Key

For the File/Folder Type, enter the Path to the object that Permissions will be applied to. For the Registry Type, enter the Hive and Key that the Permissions will be applied to.

Force use of 32-bit registry locations on 64-bit operating systems

Check this box to force the 32 bit registry location to be used instead of the 64 bit location, when executing on 64 bit operating systems.

Inheritance

Select Do not modify this object's inheritance, Allow this object to inherit from parent, Do not allow this object to inherit from parent and discard inherited permissions, Do not allow this object to inherit from parent and copy inherited permissions from the Inheritance list. The Inheritance selection defines how or if permissions for the object will be inherited.

  • Do not modify this object's inheritance - This object will not assume (inherit) permissions from any other object.
  • Allow this object to inherit from parent - This object is allowed to assume permissions from its parent object.
  • Do not allow this object to inherit from parent and discard inherited permissions - This object will not be allowed to assume permissions from its parent object. If the object already has inherited any parent permissions they will be removed.
  • Do not allow this object to inherit from parent and copy inherited permissions - This object is not allowed to assume (inherit) permissions from its parent object, nor is it allowed to copy permissions from its parent.
Permissions

The Permissions list designates which users and/or groups will be given permissions to the selected object (File/Folder or Registry)

Press Add to define users and/or groups to which permissions will be given to the selected object. Press Edit to edit an entry in the Permissions list. Press Delete to remove an entry from the Permissions list.

Figure 25: Creating permission sets

Once in Add/Edit mode update the following entries:

Principal

Specify a user or group that will be assigned the designated permissions.

SID

The SID (Security Identifier) will be automatically populated once a Principal is selected.

Permissions

The permission boxes represent the standard permissions that can be allowed or denied for the specified Principal. Select Allow to permit access to the object. Select Deny to refuse access to the object. Selecting either Allow or Deny Full Control will automatically select the Read, Write, Execute and Modify permissions.

Propagation

Select Apply to this object only, Apply to this object and child objects one level deep, Apply to this object and allow all child objects to inherit, or Apply to this object and apply to all child objects from the Propagation list. The propagation selection defines which components (Parent and/or Child) of the object are affected by the Permission change.

  • Apply to this object only - Permissions are applied to the selected Path or registry Hive/Key only. No child objects are affected.
  • Apply to this object and child objects one level deep - Permissions are applied to the selected Path or registry Hive/Key object and to any container immediately within this object.
  • Apply to this object and allow all child objects to inherit - Permissions are applied to the selected Path or registry Hive/Key object. All child objects have the ability to inherit these permissions however the child objects are not given these permissions automatically.
  • Apply to this object and apply to all child objects - Permissions are applied to the selected Path or registry Hive/Key object and to any all containers below this object.
Child object to include

Select Files, Folders, or Files and Folders from the list. The selected child object(s) will be included in the propagation of the applied permissions.

Validation Logic

Select the Validation Logic tab to set the validation rules for this element.

Notes

Select the Notes tab to create any additional notes needed to document the profile element.

Description

When adding or modifying a profile object element, the description appears above the settings tab. Enter a description to annotate the element. The default value for new profile elements can be changed by going to the system Preferences.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating