Need a tool to clear share permissions on Windows NT
Posted on 2008-02-12
File Server: WINDOWS NT Server
I have a Windows NT Server which also acts as a file server. We have about 200 user home directories which are individually shared. Currently we are migrating the domain and the user accounts have been created in the new domain. My boss has asked me to reassign the share level permissions on these 200 home folders so that
1. Only the user has change access (account from Old domain)
2. Domain Admins have Full access (from old domain)
3. The user has change access (accout from new domain)
4. Delegated Group in AD (from new domain) has Full access
Now the trouble is, a lot of these shares have incosistent permissioning. The users had Full control earlier and because of that they started giving permissions to others. So its a real mess. I have the old user and new user accounts from 2 domains in a text file, I have all the share names and paths in the text file and what I want to do is go one by one on each share and clear all the ACE from shares. Then assign the above 4 ACEs. Obviously I want to script this operation however my problem is this
RMTSHARE - works good for assigning and removing specific SIDs but desn't give me to option to clear all ACEs from share.
SUBINACL - I used the version 5. something and it doesn't work on NT. the earlier version doesn't seem to have the /SHARE option.
So how what tool can I use to clear all ACEs in share ? (Note: This question is for share permissions only, please donot reply with solutions like Xcacls etc. I'm not doing anything on NTFS side right now)
Also I dodnot need the script. If anyone knows any tool I can use to clear ACEs? thats what I would like to know. Thanks, Gaurang