Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


file shares NTFS

Posted on 2004-09-30
Medium Priority
Last Modified: 2011-04-14
What is the best method for assigning permissions to a subfolder within a share

Shared folder has permissions everyone FULL, and NTFS Authenticated Users (everything but Full control)

Beneath the share is about 10 subfolders that inherited the permissions of the share.  One of the subfolders need to have special access - only access from a specific group

I know it is proper to configure shares as AGLP, but this doesn't seem to follow that process because it is a subfolder.  

What is the best method for handling these types of share issues.  Create an additional share from the folder and assign it permissions?


Question by:vivo123
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 76

Accepted Solution

David Lee earned 500 total points
ID: 12196497
If the permissions on a single folder under a share needs to be changed, then in my opinion the best way to handle it is to block inheritance at that folder and alter the permissions to whatever they need to be.

Author Comment

ID: 12199813
should I assign just the users that need access or create a G Group and assign that to the folder under the share.  

It seems that I should only assign users, but I want to follow proper methods.

LVL 76

Expert Comment

by:David Lee
ID: 12199873
It's always best to assign permissions to groups, not individuals.  I'd create a group, add the necessary user accounts to it, and grant that group permissions.

Author Comment

ID: 12200993
Thanks again..  one more thing, I know I am beating this to death.. On a single folder under a share would you just assign a global group permissions to that folder, or would you actually assign a DL group or Lgroup and assign the global group to that DL or Lgroup even though it is not the main share.  Or do you only assign the DL or Lgroup w/ the appropriate GGgroup to the MAIN Share.

Hope this makes sense..
LVL 76

Expert Comment

by:David Lee
ID: 12201805
I wouldn't start nesting groups unless there's a compelling reason to do so.  For example, if you're in a multiple domain environment and some folks from another domain need access to the share also.  

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question