How are permissions on default administrative shares controlled?
While the NTFS ACLs on those items are permissive, the share ACLs on these default system shares are always set to allow just the local Administrators
group (which contains the Domain Admins
group).
The permissions on these items cannot be modified.
The permissions for those default admin shares are hard coded in Windows and can't be changed (at least not successfully).