Solved

User with Full Control unable to delete files in Server 2000 network share

Posted on 2008-06-24
13
365 Views
Last Modified: 2013-12-05
I'm doing some housekeeping on one of our servers and in the process trying to delete shared folders belonging to ex-employees. I have assigned Full Control rights to these folder to supervisors of the ex-employees. When the supervisors try to delete items from the folders they get an error message stating they do not have permission to delete the file. What do I have to do to allow one user to delete files in the shared folder of another user?

This is occurring on a Windows 2000 Server in a 2003 Domain. Client PC are Windows XP. The share is the users home share on the network.

Thanks for any help
RickKnight
0
Comment
Question by:RickKnight
  • 7
  • 6
13 Comments
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21858884
Check the permissions on the share as well as any NTFS permissions, as Windows will grant the least permissive combination of the 2.  I.e., if a user has Read permissions at the share level and Full Control NTFS perms, their effective permission set will be Read, not Full Control.
0
 

Author Comment

by:RickKnight
ID: 21859066
Thank you for the reply,

I hate to sound like a dummy, but what are NTFS permissions as opposed to the Share permissions and Folder Properties > Security settings?

Thanks again,
RickKnight
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21859092
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 

Author Comment

by:RickKnight
ID: 21859822
Thanks for the link. I read the article and another article by the same author, http://www.windowsecurity.com/articles/Understanding-Windows-NTFS-Permissions.html.

As I understand NTFS permissions, I have the user configured with these NTFS permissions...

Full Control
Modify
Read & Execute
List Folder Contents
Read
Write

I have the Share permissions set for "Authenticated Users" ...

Full Control
Change
Read

I assume the NTFS permissions are accessed in the Security tab of the file or folder Properties dialog? Is this correct? What else do I need to do to allow the user to delete files and folders?

Thanks again,
RickKnight


 
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21859859
Based on that combination, the user should be able to delete the files/folders in question.  If they are not, instruct the user to take ownership of the files/folders and attempt to delete them again. Also confirm that the files/folders have not been flagged as read-only or encrypted.
0
 

Author Comment

by:RickKnight
ID: 21860068
I've tried to have the user take ownership of the folder/files. That also does not work. The user gets a message saying they only have permission to view the security settings.

The files are neither compressed nor encrypted.

Thanks,
RickKnight
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21860097
Then you do not have your permissions configured as you have described above.  A "Take Ownership" operation requires Full Control permissions; if it fails, the user does not have Full Control. (Given this, a delete operation will likely succeed without taking ownership once you rectify the permission assignment to Full Control.)
0
 

Author Comment

by:RickKnight
ID: 21860200
I have configured this user with these permissions on the Security tab of the Properties dialog of the folder...

Full Control
Modify
Read & Execute
List Folder Contents
Read
Write

Under the Advanced button in View/Edit, every permission is set to allow including Take Ownership.

Where else do I need to set the permission?

Thanks,
RickKnight
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21860222
Confirm that there are no other permissions configured at the same level that would conflict, particularly a Deny entry.  Also re-confirm share permissions if applicable.
0
 

Author Comment

by:RickKnight
ID: 21860302
There Share Permissions are, Authenticated Users, Allow Full, Change & read. The NTFS Permissions for this user are Allow Full Control, Modify, Read & Execute, List Folder Contents, Read, Write. There are no Deny entries.

This Share is inside another share that has more restrictive permissions. The upper level share has "Authenticated Users" Allow Read only. No other Allow entries and no Deny entries. Also the upper NTFS Permissions do not include this user. Could the more restrictive share permissions on the upper level folder be causing this problem?

Thanks again,
RickKnight
0
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 500 total points
ID: 21860375
If the files are being accessed using the UNC of the more restrictive share, then the more restrictive permissions will apply.
0
 

Author Comment

by:RickKnight
ID: 21860405
Yes, I am having the user access the share as \\strocal-2\home\CSchmidt wher CSchmidt is the share with the problem and home is also a share.

I can have the user try as a mapped drive pointing directly to the CSchmidt folder.

0
 

Author Comment

by:RickKnight
ID: 21861017
Thanks,

That's the answer. When I mapped the share as drives, the users do have Full Control.

Thanks for your help,
RickKnight
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question