Solved

Server 2008 NTFS Permissions

Posted on 2009-05-05
4
835 Views
Last Modified: 2012-05-06
I have two issues; Im building a 2008 file server,
1.      The issue is in 2008, I've created a new drive and the permissions are; creator owner, everyone, systems, administrators, users (server).  When I remove the users and everyone, I can longer get into the folder, permission is denied, though I'm a domain admin and yes the domain admin is in the servers local admin group.  
2.      I dont mind inheriting permissions, but I want to be able to copy over permissions and then remove those users/groups I do not want, but I dont see anyway.
0
Comment
Question by:Puke Foo
  • 2
  • 2
4 Comments
 
LVL 58

Accepted Solution

by:
tigermatt earned 500 total points
ID: 24307992

> #1

This is by design. In your 'normal' user token (before having elevated at a UAC prompt) you do not have any Administrator privileges. Therefore, the Administrator group does not apply, and you are denied access.

If you elevate a UAC prompt or run a program as Administrator, that is the only time you have true Admin privileges on your account and will have access to the drive.

Currently, this is a known issue with Windows Server 2008 and NTFS file permissions. At present, the only way around this is to make the user a member of another, custom group which has the permissions assigned on the drive. This will give you access to the drive without elevating at UAC.

> #2

I'm not too sure what you're talking about. If you need to copy files between servers/shares and retain their NTFS permissions, look at the robocopy tool with the /COPYALL switch.

-Matt
0
 

Author Comment

by:Puke Foo
ID: 24308703
The first answer is perfect, thank you.  

The second, I'm referring to server 2003, if I choice to not inherent permissions I can uncheck "allow inheritable from the parent to propagate etc..." then I get the option of copy or remove.  I choice copy and then remove the group/users or add the groups/users I want.  I don't seem to be able to accomplish this.  I can't choose to remove inheritable permissions, anyone know how?
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24318393

So to clarify matters, if you uncheck the inherit option, and you press 'Remove', no permissions are removed?

-Matt
0
 

Author Comment

by:Puke Foo
ID: 24453096
I've figured it out with your help thanks tigermatt
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question