[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Set permission on users home directory.

Posted on 2009-04-09
5
Medium Priority
?
762 Views
Last Modified: 2012-06-27
Hello,

I am trying to set permissions on the users home directory to only allow users to view their own created directory. I have set the permissions as follows
Shared folder called users$ set permissions to domain admins/full  and domain users/ read+change
under security I have set the same I click advanced, select domain users and click edit make sure that traverse, list, read permissions are set and make sure that allow inheritable is unchecked, i check the replace permissions entries...
When I select a user and windows explorer and manually type in \\server\users$ i can open all folders the user is a test user and allow belongs to the domain users group.

I need to block access to all users they should have access of their own folders only even if they manually type in the address in windows explorer.

Any ideas?

Thanks
0
Comment
Question by:sammy_bull
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 24109226
Set the permissions so that you have the least effort with it, for example like this for user JDoe:
Users: Local(!) Administrators:Full, System:Full, Local(!) Users:Read ("This folder only" in Advanced properties);
  +-- JDoe: Local Administrators:Full (inherited), System:Full (inherited), JDoe:Full (or Change)
0
 

Author Comment

by:sammy_bull
ID: 24110052
Sorry!

I am having difficulty understanding what you suggested. Do I set the permissions on the share tab or on the security tab. I think you mean security tab. Do you also mean I would have to do the joe part on each user folder?

Thanks
0
 

Author Comment

by:sammy_bull
ID: 24110092
I am creating an empty folder called users$ on another server. What would i need to set for the permissions. So that way when i log in with a user it is automatically set.

Thanks
0
 
LVL 85

Accepted Solution

by:
oBdA earned 1000 total points
ID: 24110667
Name the folder just Users; you can add the $ at the end of the share name, but note that hiding a share does *not* add any security.
Share the folder, and give Everyone Full Control in the *share* permissions (no need to use both Share and NTFS permissions).
Open the NTFS permissions of the folder, go to the Advanced tab, disable the permissions inheritance for the folder, click OK to close the Advanced dialog.
Remove all accounts that currently have permissions except the local(!) Administrators group (should have Full Control), the local System account (should have Full Control), and the local(!) Users group (should have Read); click Apply.
Re-open the Advanced properties, highlight "Users", and change the "Apply to" dropdown box to "This folder only". Close the permission dialogs.
When you now add a user folder, you only have to add the user account, without having to break inheritance, and you still have the ability to add, for example, a helpdesk group to Users, with the permissions being inherited down to the user folders.
A home folder will never be created upon logon. If one doesn't exist, it will be created as soon as you specify the path in the user's properties in ADUC, but the permissions given there usually aren't that usable. In the long run, you're better off simply creating the home folder before you create the user, and add the account to the permissions as soon as the user is created (or create the user, including the home drive and other default settings it needs, with a script).
0
 
LVL 18

Expert Comment

by:Americom
ID: 24116117
I would suggest you follow oBdA's suggestion above.
Manage permission by Security(NTFS) and leave full control on the Share permission.
If you care what permission user has on his/her own folder, don't even bother to create the folder via the profile tab under the user account properties as that will allow users with full control to their folder that would make your life miserable. So, setting up \\server\users or \\server\users$ will be the root, then user home folder will be under.
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question