Active Directory: configuring dynamic access control – DAC


Windows Server 2012R2 Windows Server 2016 Windows Server 2019

Dynamic Access Control Test - DAC

Now that the configuration is complete, we will move on to testing. For the tests I used a Windows 10 client computer and two users:

  • user1.it: member of the GRP_USERS_IT group which must therefore have permission to open the file.
  • user1.hr : not member of the group, he must not be able to open the file.

Test 1 with user1.it

With this user, the document Commun_1 which contains the word DSI opens.

Test 2 with user1.hr

With this user, the document Commun_1 which contains the word DSI does not open because it is not part of the GRP_USERS_IT group, on the other hand it can open the other documents which do not have the File with DSI word property set to yes. We can see below that an error message is displayed.


Dynamic access control works, we will now see how to customize the error message.



Comments are not currently available for this post.