Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Active Directory Folder Permissions

Posted on 2007-04-11
3
Medium Priority
?
535 Views
Last Modified: 2013-12-04
We are Using Windows 2003 Server with Active Directory

The question is we have a folder below the Home folder (Home = Users)

So someone made a folder below the HOME(USERS) called PCP

Then 3 other folders were made.  Below is the example of what we are trying to accomplish.
As of now since the permissions for GroupShareUser are inherited it shows that Joe can Write to Sue and Marks folder.  We want Joe to only be able to Write to his folder but read the content in all other folders.
Can we deny the Write permission for the GroupShareUser and then the Folder Level User Write permissions for Joe will Take control?


PCP FOLDER

Joe FOlder

Sue FOlder

Mark FOlder

JOe should be able to Read/W/E in Joe FOlder  BUt can only Read Sue and Mark FOlder

Sure should be able to READ/W/E in Sue Folder But can only Read Joe and Mark Folder
0
Comment
Question by:cybersharks1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 67

Accepted Solution

by:
sirbounty earned 500 total points
ID: 18893301
Unless you're going to explicitly deny every user (don't deny Everyone from writing - that'll include Joe!), you are better off just not adding those rights...

In other words, remove inheritence from Joe
Then under Security/Advanced, edit the permissions (copy) and remove anyone besides Joe that doesn't need any access.
You can then come back in and Add Everyone:Read if needed...
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Let's recap what we learned from yesterday's Skyport Systems webinar.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question