Solved

NTFS security - Folder Security

Posted on 2004-09-08
11
1,529 Views
Last Modified: 2010-08-05
Hi!
I don't want the users in the network to be able to create, delete og remove folders at root level at our server.

We have 6 folders at root level which "domain users" are NOT supposed to create, move or delete files or folders at this level. (Wich they often do by mistake)

All users are members of "domain users".

I have tried to give the users restricted acces to the folders, but it has not succeded.
Eighter they gets denied, or they still get full access.

 Sharing permissions tab shows "Domain Users" "Full Control" , "Change" , " Read".
Security tab shows "Authenticated Users" and "Domain Users" - Modify - Read & Execute - List Folder Contents - Read - Write.

Advanced Settings: Access Control Settings: Deny "Users" , Deny "Authenticated Users" - Change permissions , take ownership.

I have tried to deny "create folders / append data , create files / write data. I applied the settings by using " Apply these permissions to objects and/or containers within this container only".      I am not getting the result I'm looking for.
Usually users don't get enough user rights, and I have to reset to "full access" so that everyone can start working again.

As mentioned above, I want to be able to deny users to do anything about the folders at root level. (6 folders which are shared). All users have mapped this folders by a loggon script. The users are not supposed to create files in theese 6 folders or above eighter.

My settings like they are right now is working in a way taht everyone gets access to the files. This is a temporary solution. Looking for a good solution. We have only 33 employees.


Anyone with long experience within this field?

TrondL
0
Comment
Question by:TrondL
  • 5
  • 2
11 Comments
 
LVL 15

Expert Comment

by:Yan_west
ID: 12006027
just give read access to your "authenticated users" at root level (folder security). that will do the trick.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12006030
btw... you will need to break rights inheritance in subfolders, because permission will be propagated..
0
 
LVL 15

Accepted Solution

by:
Yan_west earned 84 total points
ID: 12006052
And if your users are members of other group, like domain users, and this group have access, they will get access to it anyways. I would give read access to "domain users", and full access to administrators. that'S it, nothing else.
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 
LVL 6

Assisted Solution

by:Eric
Eric earned 83 total points
ID: 12006164
Make the Root Folders "read only"
then inside the folders change the permissions of the folders/files to the security that you have.  

make sure that the child folders dont inherit permissions from the parent..

example:

root1:    <- read only
- child1:  <-- full control
- child2:  <-- full control

root2:    <- read only
- child1:   <-- full control
- child2:   <-- full control




basically the design is make sure the door to the room is secure, but the information behind the door is wide open once the people are inside.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12006360
Hey, that'S what I wronte ;)
0
 
LVL 6

Expert Comment

by:Eric
ID: 12006445
sorry bout that man..  i read the question, and just started typeing an answer in..  didn't even dawn on me to look at what had been written.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12006525
lol... It happens to everyone
0
 
LVL 4

Assisted Solution

by:averyb
averyb earned 83 total points
ID: 12011448
I am not sure about your config.

You say "I want to be able to deny users to do anything about the folders at root level. (6 folders which are shared). All users have mapped this folders by a loggon script."  

Which folders are actually shared on your server?
Is there one shared folder that contains the 6 folders?  
Or are there 6 different shared folders?

If all 6 folders are shared individually, then the only way they could get to the root (i.e. above those share points) is if there is another share defined for the root itself.

What are your client computers?  This can make a difference.

How do you map the drives?  Can you post the net use commands from the login scripts?





0

Featured Post

Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Oracle DB Slows After Datapump Until Next Reboot 27 122
Palo Alto site-to-site vpn monitoring 5 46
Boot Camp 3 55
AD Design Best Practices 6 32
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question