Solved

NTFS Permissions - Create Files/Folder no delete

Posted on 2007-03-19
2
2,774 Views
Last Modified: 2013-12-05
Goal: Allow a group to create files & folders in a share, but do not allow them to delete files or subdirectories (even ones they created).

Issue: unless they have "delete" they cannot rename the files/folders.  Apparently the rename option does not really allow them to rename unless delete is checked.  If they have delete they can delete their own items they've created and we don't want that.

Tested the Share rights with both:  Read/Modify and read only
NTFS permissions: all except delete, delete files and folders, change permissions, and take ownership.  Given this, the user is supposed to be able to rename files/folders.

Observed: "delete" must be checked to rename files/folders on the share.

Is this the way it works or am I missing something?

0
Comment
Question by:katfpi
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 25 total points
ID: 18750709
Just tested this on my system and you are correct.  Apparently, removing Delete and Delete Files and Folders from the NTFS permissions prevents changing the file/folder name.  Weird....BTW, just so you know, if you check both of these items, you also can't move a file/folder, so this must be the same issue.  I guess renaming the folder must trigger a background copy / paste with new name / delete original folder action.  I know this is what move does - the background action is really to copy the original folder / delete the original folder / paste the copy into the new location.
0
 
LVL 25

Assisted Solution

by:mikeleebrla
mikeleebrla earned 25 total points
ID: 18750864
no you are not missing anything.  As long as a user has 'modify' rights (which most will have so they can edit files) then they can also delete them (and also move them elsewhere by the way).  That is just the way the OS is designed.  Wierd i know.


>>(even ones they created).
if they created it, then they are the 'owner' and can do whatever they please.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip Migration Tip #1 – Source Server Health can be found listed in my profile here: http:…
Welcome to my series of short tips on migrations. Whilst based on Microsoft migrations the same principles can be applied to any type of migration. My first tip Migration Tip #1 – Source Server Health can be found here: http://www.experts-exchang…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

622 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question