New functionality enables WinRMRemoteWMIUsers__ group members to remotely view file share permissions in Windows 8 or in Windows Server 2012

Applies to: Windows 8Windows 8 EnterpriseWindows Server 2012 Datacenter

Summary


In Windows 8 and in Windows Server 2012, a new Share tab is added to the Advanced Security Settings UI. This tab displays the security properties of a remote file share. In order to view this information, you must have the following permissions and memberships, as appropriate for the version of Windows Server that the file server is running.

The file share is hosted on a server that is running Windows Server 2012
  • You must be a member of the WinRMRemoteWMIUsers__ group or of the BUILTIN\Administrators group on the server that hosts the file share.
  • You must have read permissions to the file share.
The file share is hosted on a server that is running a version of Windows Server that is earlier than Windows Server 2012
  • You must be a member of the BUILTIN\ Administrators group.
  • You must have read permissions to the file share.

More Information


In Windows Server 2012, the Access Denied Assistance functionality adds the Authenticated Users group to the local WinRMRemoteWMIUsers__ group. Therefore, when the Access Denied Assistance functionality is enabled, all authenticated users who have read permissions to the file share can view the file share permissions.