# Inspect inherited DFS visibility permissions before relying on access-based enumeration

> Why can DFS folders remain visible after access-based enumeration is enabled?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:18+00:00
- Modified: 2026-09-08T18:20:21+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Why can DFS folders remain visible after access-based enumeration is enabled?

## Potentially affected

Use this review when DFS namespace visibility differs from the intended user experience.

## DSE recommendation

Write a visibility matrix for representative users and folders.

## Article

## Source facts

Microsoft explains that DFS folder visibility permissions can inherit from the namespace server’s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration).

## Applicability

Use this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.

## DSE recommendation

Write a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.

## Verification

Inspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.

## Official references

[Microsoft Learn: Using Inherited Permissions with Access-based Enumeration](https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration). Source reviewed September 8, 2026.

## Primary reference

- Name: Using Inherited Permissions with Access-based Enumeration
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/dfs-namespaces/using-inherited-permissions-with-access-based-enumeration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Inspect inherited DFS visibility permissions before relying on access-based enumeration,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-053-inspect-inherited-dfs-visibility-permissions-before-relying-on-access-based/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
