Problem
Another administrator was attempting to give a user access to a subfolder on then secondary drive (D:) of a Windows Server 2019 Core VM. Instead he somehow locked everyone out, including other Administrators. Trying to navigate or perform most actions on the D: directory results in an "Access is Denied" error.
Solutions and Commands We've Tried
Any variation of the following commands:
- Takeown (ex.
takeown /F d: /r /d y
) - ICACLS (ex.
idacls D:
,icacls "D:" /Reset /T /C /L /Q
) - Get-ACL
- Additionally, I've tried installing pstools, elevating myself to system via
psexec /ids cmd
orpsexec -i -s cmd.exe
and running the same barrage of commands.
All return: "Access is denied".
Finally I tried installing the PowerShell Module called NTFSSecurity Using this module, I executed the following cmdlet:
Get-ChildItem -Path D:-Recurse -Force | Set-NTFSOwner -Account '<my AD administrator account>'
From here I was able to access the D:\ drive, but after attempting to run a second cmdlet to try to reset the entire directory:
Get-ChildItem -Path C:\Temp -Recurse -Force | Clear-NTFSAccess
I seem to have lost access again. Running the first NTFSOwner cmdlet does not fix the access issue.
Further NTFSSecurity Information
- Running
Get-NTFSOwner D:
returnsBUILTIN\Administrators
as the owner. - Running
Get-NTFSAccess D:
returns a fair amount of information, including that D:\ has inheritance enabled, and that bothNT AUTHORITY\SYSTEM
andBUILTIN\Administrators
have FullControl Access Rights to D:\, but none of it's subfolders. - I successfully gave my AD account access via the Add-NTFSAccess command, with Full Control over D: and all subfolders, but I'm still unable to access the drive.
All AD Administrative accounts should have full reign over the system, but we all seem to be locked out. I'm personally at a loss here, but there has to be something I'm missing. I was able to get access to D: after initially running the NTFSOwner cmdlet but, regrettably, it seems I may have ruined that after clearing NTFS-Access.
Any help would be greatly appreciated.