file sharing permissions in widnows 2003 domain

Hello all,

Our setup is Windows 2003 domain.  On one of our servers we have some shared folders.  I would like to allow our users to only view the contents of the folders, and not have the ability to open the files.  This will allow us (as admins) to start keeping track of how often this data is used.

I was able to accomplish this in a workgroup by going under the Security tab of a folder and uncheck all but "List Folder Contents" checkboxes for the particular user/group.  It seems that from my testing the file sharing permissions are set under the Sharing tab and not the Security tab.

Is there a way to only allow users to list contents of a specific folder in a windows 2003 domain?

nix-IT
nix-ITAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

nix-ITAuthor Commented:
anyone?
0
Kevin HaysIT AnalystCommented:
In a domain I would suggest you implement the shared folders according to this.

Share the folder and give everyone full control.
NTFS tab is where you control the security.
Remove all permissions and groups from the security tab and start by adding in the local machine\administrators = full control
domain\administrators = full control
system = full control
domain users = list folder contents / read data

Of couse you would replace domain users with whatever group you want to have that permission.

To get to this point do the following.
Right click on folder, properties, <sharing> and share the folder and add everyone=full control
<security> advanced, uncheck the inheritable permissions and then click remove.
Start adding in those groups I suggested to start with.

Kevin
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
nix-ITAuthor Commented:
Thanx, I had everything but the "Full Control" setting in sharing, which is why (I'm assuming) it wasn't working.  

Even though we don't want to give our users READ access, I can mess with the permissions in under the security tab to give us appropriate privileges.  Thanks so much for you help.

0
Kevin HaysIT AnalystCommented:
yeah, that's the problem then.  You always want to assign the everyone group under the "sharing" tab to full control and then you control who gets what access via the "security" tab :)  It is just so much easier to control and audit that way.
Anytime, glad I could help and thanks for the grade!
Kevin
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.