A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?
In Windows ACL evaluation, an explicit Deny ACE is evaluated before any Allow ACE, regardless of whether the Allow comes from group membership or inheritance. Because Alice's user account has a direct Deny on 'Read & execute', that deny overrides the Modify permission granted to her group, preventing her from opening the file. This is a fundamental rule of Windows access control.
Why this answer
Windows evaluates explicit Deny ACEs before Allow ACEs, and this precedence applies even when the Allow comes from group membership. An explicit Deny on a user account directly blocks the permission, overriding any group-based Allow. The analyst's observation of the explicit Deny on Alice's account explains why she cannot open the file despite her group having Modify.
Exam trap
The trap here is assuming that group-based Allow permissions can override a direct Deny on a user account, when in fact explicit Deny always wins.