{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
        "slug": "dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/"
        },
        "title": "Inspect inherited DFS visibility permissions before relying on access-based enumeration",
        "summary": "Why can DFS folders remain visible after access-based enumeration is enabled?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:18+00:00",
        "modified_at": "2026-09-08T18:20:21+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 238,
        "potentially_affected": "Use this review when DFS namespace visibility differs from the intended user experience.",
        "dse_recommendation": "Write a visibility matrix for representative users and folders.",
        "primary_source": {
            "name": "Using Inherited Permissions with Access-based Enumeration",
            "url": "https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft explains that DFS folder visibility permissions can inherit from the namespace server&#8217;s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. <a href=\"https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.</p>\n<h2>DSE recommendation</h2>\n<p>Write a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.</p>\n<h2>Verification</h2>\n<p>Inspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Using Inherited Permissions with Access-based Enumeration</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft explains that DFS folder visibility permissions can inherit from the namespace server’s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. Microsoft documentation.\nApplicability\nUse this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.\nDSE recommendation\nWrite a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.\nVerification\nInspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.\nOfficial references\nMicrosoft Learn: Using Inherited Permissions with Access-based Enumeration. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft explains that DFS folder visibility permissions can inherit from the namespace server’s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration).\n\n## Applicability\n\nUse this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.\n\n## DSE recommendation\n\nWrite a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.\n\n## Verification\n\nInspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.\n\n## Official references\n\n[Microsoft Learn: Using Inherited Permissions with Access-based Enumeration](https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Inspect inherited DFS visibility permissions before relying on access-based enumeration",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/",
                "headline": "Inspect inherited DFS visibility permissions before relying on access-based enumeration",
                "description": "Why can DFS folders remain visible after access-based enumeration is enabled?",
                "abstract": "Why can DFS folders remain visible after access-based enumeration is enabled?",
                "articleBody": "Source facts\nMicrosoft explains that DFS folder visibility permissions can inherit from the namespace server’s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. Microsoft documentation.\nApplicability\nUse this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.\nDSE recommendation\nWrite a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.\nVerification\nInspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.\nOfficial references\nMicrosoft Learn: Using Inherited Permissions with Access-based Enumeration. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:18+00:00",
                "dateModified": "2026-09-08T18:20:21+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Inspect inherited DFS visibility permissions before relying on access-based enumeration"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 238,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Using Inherited Permissions with Access-based Enumeration",
                    "url": "https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration"
                }
            }
        ]
    }
}