Solved

The Permissions Challenge

Posted on 2007-03-23
7
256 Views
Last Modified: 2011-09-20
Windows 2k3 Sbs Server
Need to setup permissions as follows:
All paths are ficticious
the server folder d:\company is shared as "company" and mapped on to clients as g:
there are loads of folders under G:
1. we want to prevent people from creating, deleting and moving files and folders IN THE ROOT folder only.
2 the sub-folders of G\ should allow the creation, deletion, movng of files and folders as people wish.
3. one of the subfolders of G\ (g:\existing clients) must be set to prevent the creation, deletion and moving of files and folders within its root only. the subfolders of g:\existing clients should allow the creation , deletion and moving of files.
I have created a sec group called g_no_modify and added the said users to that group.
any help would be apreciated as i have already lost all my hair over this

Cheers

0
Comment
Question by:ivicker
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
7 Comments
 
LVL 16

Expert Comment

by:AdamRobinson
ID: 18779159
Apply the permissions from the first root.

Break the inheritance (but COPY the permissions downstream).

Change the permissions on the root to your restricted version.

Do the same process for your subfolder.

That should achieve what you're wanting.
0
 

Author Comment

by:ivicker
ID: 18781080
I have tried this already, but it still doesnt prevent me from partially moving a folder from the root to a child folder.
any other suggestions
0
 
LVL 16

Expert Comment

by:AdamRobinson
ID: 18782279
Unfortunately for "move" you have to set an explicit permisssion on the folders you don't want moved, which you'll have to stop from inheriting -- using deny to stop the move on the explicit NTFS permission.

0
 

Author Comment

by:ivicker
ID: 18842887
When I set the permissions, when I set the deny delete, it also prevents me from creating new folders. is there any way for this to be implemented at all?
Basicly I want my users to be able to create files and folders, but not delete them afterwards, does this make sense, is it possible? HELP!!
0
 
LVL 16

Accepted Solution

by:
AdamRobinson earned 125 total points
ID: 18843273
I do not believe what you are asking to do is possible under NTFS permissions.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The articles for turning off the Client firewall policy on the internet are for SBS 2008 and don't really help for SBS 2011. They actually moved the Client firewall policy. In 2011, the client firewall policy has moved to the SBS computers conta…
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question