Solved

Allow Write Permissions to a C: drive folder in Group Policy on win2k

Posted on 2009-06-30
5
2,139 Views
Last Modified: 2012-08-13
Is there a way to set up in group policy for users to be able to write to a folder on their C: drive?  I don't have users set up as local admins and would like to keep it that way and I didn't want to have to go into every machine and change the permissions on each folder.
0
Comment
Question by:cbish21577
  • 3
  • 2
5 Comments
 
LVL 83

Expert Comment

by:oBdA
ID: 24748747
Yes, that's possible. Just apply a GPO to the machines in question, and add the folder in Computer Configuration\Windows Settings\Security Settings\File System. Note that you don't need to be able to browse to the folder, you can just enter the full local path (in case the folder doesn't exist on the machine you're running the GPMC on).
Apply or modify permission entries for objects using Group Policy
http://technet.microsoft.com/en-us/library/cc756952(WS.10).aspx
0
 

Author Comment

by:cbish21577
ID: 24748821
So I would just add C:\program files\blah in Computer Configuration\Windows Settings\Security Settings\File System?
0
 
LVL 83

Expert Comment

by:oBdA
ID: 24748852
And add the necessary permissions in the dialog afterwards, yes. I'd create a domain local group "NTFS_Blah_C" or whatever and assign this group Change permissions, then add the required users or groups to this group.
You might want to try it with a test folder on a test client first before you go into production.
0
 

Author Comment

by:cbish21577
ID: 24749120
I'm confused as to adding C:\program files\blah in Computer Configuration\Windows Settings\Security Settings\File System.  I'm on my win2k server and in Group Policy and I'm under  Computer Configuration\Windows Settings\Security Settings\File System but I'm adding C: drive.  Isn't that referring to the servers c: drive and not the local machines I want to grant some access too?  I've added this all and selected everything I can imagine that is associated with the test computer and test user to give permission and nothing is working.
0
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 24749219
No; the client side extensions of the group policy will see the C: reference and set the permissions on this local path.
The test user is of no importance; the GPO has to be applied to a *computer* object.
Assuming you have XP clients: apply the GPO, logon with an admin account to the XP machine, open a command prompt, enter
gpupdate /target:computer /force
The permissions on the folder should change to the ones defined in the GPO.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Adding Computers to AD groups through an SCCM Task Sequence
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question