WSS_ADMIN_WPG has read and write access to local resources. The application pool accounts for the Central Administration and Timer services are in WSS_ADMIN_WPG. The following table shows the WSS_ADMIN_WPG registry entry permissions.
|
Key name
|
Permissions
|
Inherit
|
Description
|
|
HKEY_CLASSES_ROOT\APPID\{58F1D482-A132-4297-9B8A-F8E4E600CDF6}
|
Full control
|
N/A
|
This is the SharePoint Server 2010 Search service COM Application.
|
|
HKEY_CLASSES_ROOT\APPID\{6002D29F-1366-4523-88C1-56D59BFEF8CB}
|
Full control
|
N/A
|
This is the SharePoint Foundation 2010 Search service COM Application.
|
|
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS
|
Full control
|
N/A
|
N/A
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Office\14.0\Registration\{90120000-110D-0000-0000-0000000FF1CE}
|
Read, write
|
N/A
|
N/A
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office Server
|
Read
|
No
|
This key is the root of the SharePoint Server 2010 registry settings tree. If this key is altered, SharePoint Server 2010 functionality will fail.
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office Server\14.0
|
Full control
|
No
|
This key is the root of the SharePoint Server 2010 registry settings.
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Office Server\14.0\LoadBalancerSettings
|
Read, write
|
No
|
This key contains settings for the document conversion service. Altering this key will break document conversion functionality.
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Office Server\14.0\LauncherSettings
|
Read, write
|
No
|
This key contains settings for the document conversion service. Altering this key will break document conversion functionality.
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Office Server\14.0\Search
|
Full control
|
N/A
|
N/A
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Shared Tools\Web Server Extensions\14.0\Search
|
Full control
|
N/A
|
N/A
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Shared Tools\Web Server Extensions\14.0\Secure
|
Full control
|
No
|
This key contains the connection string and the ID of the configuration database to which the machine is joined. If this key is altered, the SharePoint Server installation on the machine will not function.
|
|
HKEY_LOCAL_MACHINE\Software\Microsoft\Shared Tools\Web Server Extensions\14.0\WSS
|
Full control
|
Yes
|
This key contains settings used during setup. If this key is altered, diagnostic logging may fail and setup or post-setup configuration may fail.
|
The following table shows the WSS_ADMIN_WPG file system permissions.
|
File system path
|
Permissions
|
Inherit
|
Description
|
|
%AllUsersProfile%\Application Data\Microsoft\Sharepoint
|
Full control
|
No
|
This directory contains the file-system-backed cache of the farm configuration. Processes might fail to start and the administrative actions might fail if this directory is altered or deleted.
|
|
C:\Inetpub\wwwroot\wss
|
Full control
|
No
|
This directory (or the corresponding directory under the Inetpub root on the server) is used as the default location for IIS Web sites. SharePoint sites will be unavailable and administrative actions might fail if this directory is altered or deleted, unless custom IIS Web site paths are provided for all IIS Web sites extended with SharePoint Server.
|
|
%ProgramFiles%\Microsoft Office Servers\14.0
|
Full control
|
No
|
This directory is the installation location for SharePoint Server 2010 binaries and data. The directory can be changed during installation. All SharePoint Server 2010 functionality will fail if this directory is removed, altered, or removed after installation. Membership in the WSS_ADMIN_WPG Windows security group is required for some SharePoint Server 2010 services to be able to store data on disk.
|
|
%ProgramFiles%\Microsoft Office Servers\14.0\WebServices
|
Read, write
|
No
|
This directory is the root directory where back-end Web services are hosted, for example, Excel and Search. The SharePoint Server 2010 features that depend on these services will fail if this directory is removed or altered.
|
|
%ProgramFiles%\Microsoft Office Servers\14.0\Data
|
Full control
|
No
|
This directory is the root location where local data is stored, including search indexes. Search functionality will fail if this directory is removed or altered. WSS_ADMIN_WPG Windows security group permissions are required to enable search to save and secure data in this folder.
|
|
%ProgramFiles%\Microsoft Office Servers\14.0\Logs
|
Full control
|
Yes
|
This directory is the location where the run-time diagnostic logging is generated. Logging functionality will not function properly if this directory is removed or altered.
|
|
%ProgramFiles%\Microsoft Office Servers\14.0\Data\Office Server
|
Full control
|
Yes
|
Same as the parent folder.
|
|
%windir%\System32\drivers\etc\HOSTS
|
Read, write
|
N/A
|
N/A
|
|
%windir%\Tasks
|
Full control
|
N/A
|
N/A
|
|
%COMMONPROGRAMFILES%Microsoft Shared\Web Server Extensions\14
|
Modify
|
Yes
|
This directory is the installation directory for core SharePoint Server files. If the access control list (ACL) is modified, feature activation, solution deployment, and other features will not function correctly.
|
|
%COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\14\ADMISAPI
|
Full control
|
Yes
|
This directory contains the soap services for Central Administration. If this directory is altered, remote site creation and other methods exposed in the service will not function correctly.
|
|
%COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\14\CONFIG
|
Full control
|
Yes
|
This directory contains files used to extend IIS Web sites with SharePoint Server. If this directory or its contents are altered, Web application provisioning will not function correctly.
|
|
%COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\14\LOGS
|
Full control
|
No
|
This directory contains setup and run-time tracing logs. If the directory is altered, diagnostic logging will not function correctly.
|
|
%COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\14\Data
|
Full control
|
Yes
|
N/A
|
|
%windir%\temp
|
Full control
|
Yes
|
This directory is used by platform components on which SharePoint Server depends. If the ACL is modified, Web Part rendering and other deserialization operations might fail.
|
|
%windir%\System32\logfiles\SharePoint
|
Full control
|
No
|
This directory is used by SharePoint Server usage logging. If this directory is modified, usage logging will not function correctly.
|
|
%systemdrive\program files\Microsoft Office Servers\14 folder on Index servers
|
Full control
|
N/A
|
This permission is granted for a %systemdrive\program files\Microsoft Office Servers\14 folder on Index servers.
|