Solved

Set permission on users home directory.

Posted on 2009-04-09
5
709 Views
Last Modified: 2012-06-27
Hello,

I am trying to set permissions on the users home directory to only allow users to view their own created directory. I have set the permissions as follows
Shared folder called users$ set permissions to domain admins/full  and domain users/ read+change
under security I have set the same I click advanced, select domain users and click edit make sure that traverse, list, read permissions are set and make sure that allow inheritable is unchecked, i check the replace permissions entries...
When I select a user and windows explorer and manually type in \\server\users$ i can open all folders the user is a test user and allow belongs to the domain users group.

I need to block access to all users they should have access of their own folders only even if they manually type in the address in windows explorer.

Any ideas?

Thanks
0
Comment
Question by:sammy_bull
  • 2
  • 2
5 Comments
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
Set the permissions so that you have the least effort with it, for example like this for user JDoe:
Users: Local(!) Administrators:Full, System:Full, Local(!) Users:Read ("This folder only" in Advanced properties);
  +-- JDoe: Local Administrators:Full (inherited), System:Full (inherited), JDoe:Full (or Change)
0
 

Author Comment

by:sammy_bull
Comment Utility
Sorry!

I am having difficulty understanding what you suggested. Do I set the permissions on the share tab or on the security tab. I think you mean security tab. Do you also mean I would have to do the joe part on each user folder?

Thanks
0
 

Author Comment

by:sammy_bull
Comment Utility
I am creating an empty folder called users$ on another server. What would i need to set for the permissions. So that way when i log in with a user it is automatically set.

Thanks
0
 
LVL 82

Accepted Solution

by:
oBdA earned 250 total points
Comment Utility
Name the folder just Users; you can add the $ at the end of the share name, but note that hiding a share does *not* add any security.
Share the folder, and give Everyone Full Control in the *share* permissions (no need to use both Share and NTFS permissions).
Open the NTFS permissions of the folder, go to the Advanced tab, disable the permissions inheritance for the folder, click OK to close the Advanced dialog.
Remove all accounts that currently have permissions except the local(!) Administrators group (should have Full Control), the local System account (should have Full Control), and the local(!) Users group (should have Read); click Apply.
Re-open the Advanced properties, highlight "Users", and change the "Apply to" dropdown box to "This folder only". Close the permission dialogs.
When you now add a user folder, you only have to add the user account, without having to break inheritance, and you still have the ability to add, for example, a helpdesk group to Users, with the permissions being inherited down to the user folders.
A home folder will never be created upon logon. If one doesn't exist, it will be created as soon as you specify the path in the user's properties in ADUC, but the permissions given there usually aren't that usable. In the long run, you're better off simply creating the home folder before you create the user, and add the account to the permissions as soon as the user is created (or create the user, including the home drive and other default settings it needs, with a script).
0
 
LVL 18

Expert Comment

by:Americom
Comment Utility
I would suggest you follow oBdA's suggestion above.
Manage permission by Security(NTFS) and leave full control on the Share permission.
If you care what permission user has on his/her own folder, don't even bother to create the folder via the profile tab under the user account properties as that will allow users with full control to their folder that would make your life miserable. So, setting up \\server\users or \\server\users$ will be the root, then user home folder will be under.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now