Executive Summary:

You can use events 528 and 540 to determine a user's logon session. Icacls can be used to generate a report of all the files that a user or group has access to. You can use Microsoft IIS to lock down certain areas of a Web site so that only certain users are permitted to access that area.

Every month, Randy Franklin Smith answers your questions about Windows security. Click the links above to see individual Q&As from this month's column. Send your questions to Randy at rsmith@ultimatewindowssecurity.com.