What you need to know
Why can DFS folders remain visible after access-based enumeration is enabled?
Potentially affected
Use this review when DFS namespace visibility differs from the intended user experience.
DSE recommendation
Write a visibility matrix for representative users and folders.
Source facts
Microsoft explains that DFS folder visibility permissions can inherit from the namespace server’s filesystem. The documented defaults grant domain users read access, so enabling access-based enumeration alone can leave every folder visible. Inherited permissions can be applied across many folders and can cover namespace roots and folders without targets. Microsoft describes changing the parent permissions or choosing explicit permissions as configuration approaches. Changes to inherited permissions do not replicate between namespace servers. Microsoft limits their use to stand-alone namespaces or environments with separate third-party ACL synchronization. Microsoft documentation.
Applicability
Use this review when DFS namespace visibility differs from the intended user experience. Identify the namespace type, servers, permission-synchronization arrangement, and parent filesystem permissions before selecting a correction.
DSE recommendation
Write a visibility matrix for representative users and folders. Have the namespace owner review the inheritance source and the scope of any proposed parent change. Keep the decision about displayed namespace entries separate from the underlying file-access authorization review. Pilot the chosen adjustment on an appropriate limited scope and preserve the original permissions.
Verification
Inspect the resulting permission source and test the namespace view with permitted and nonpermitted users. Check neighboring folders that may share the same parent inheritance. Separately test the underlying resource access specified in the plan. Record unexpected visibility or access results and resolve them before expanding a parent-level permission change.
Official references
Microsoft Learn: Using Inherited Permissions with Access-based Enumeration. Source reviewed September 8, 2026.
Review the official source
Using Inherited Permissions with Access-based Enumeration · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE