With our applications we permission certain directories with user, Power User and Administrator. In the Lock Permissions table these are represented by 1180073, 1180095, and 268435456 respectively.
However if we need a user to have modify access, and leave the system to generate a number for this, 537002431, it is not accepted on the client site. Is this to do with inheritance, their slightly different AD environment??

Any suggestions welcome
0 Comments   [ - ] Hide Comments


Please log in to comment

Rating comments in this legacy AppDeploy message board thread won't reorder them,
so that the conversation will remain readable.
Answer this question or Comment on this question for clarity


Probably.. have you read the SDK info on the lockpermissions table?

"Permission can only be set in the LockPermissions Table for users that already exist on the computer or domain. An attempt to set permissions for an unknown user causes the installation to fail, even if that user account is created during the installation by a deferred custom action."

Why not use something like setacl to do the job? It's much more flexible..

Good luck :-)
Answered 10/11/2005 by: MSIPackager
Third Degree Black Belt

Please log in to comment
Thanks for your reply Rob but i think you've misenterpreted my question.
I was worried about getting it across in writing.
Answered 10/12/2005 by: oreillyr
Fifth Degree Brown Belt

Please log in to comment