Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Windows 2003 file permission question

Posted on 2009-12-30
Medium Priority
Last Modified: 2012-05-08
Hello Windows experts !

I run into a problem with one of my Windows 2003 shared folder.  

I have a folder containing 30 GB of data (subfolders and files) which is shared by a group of 9 users.  This share is mapped on their local XP stations as Z:\share

I am trying to give everybody in this group(9 users)  the following permissions/abilities
    -read a file
    -write to a file (append data) and then re-save it
    - create folders under Z:\share
     - copy files to and from  their local workstations
I DO NOT want them to be able to delete the files/folders under Z:\share

I have tried different set of permissions but no luck so far. Here is it (see attachment called Permission).  These are at C:\share level and propagated down to the last file

The problem is that a member of the group can open the file but I cannot save it.  If I gave them Modify rights then they can save it but it seems that they can deleted the file

Any idea will be much appreciated. Thank you in advance and Happy New Year

Best regards

Question by:Bibecu
LVL 31

Accepted Solution

Henrik Johansson earned 600 total points
ID: 26147773
A problem when removing the delete permission is that Office applications expects to be able to delete temporary files created in the same folder as the document file to be able to save to files correctly. If not able to delete the temporary files, the application will classify the folder as readonly.
So, your permissions are correct, but it will prevent some applications to work as expected if not possibly to get the temporary files to be stored in %TEMP%

Assisted Solution

L3370 earned 400 total points
ID: 26148583
This probably isn't what your trying to accomplish, but thought I'd suggest it anyway.
Would it be an acceptable solution to say... make 9 separate folders under Z drive share for each individual? You can give each individual read/write access to their own folder so they can make necessary changes. Then give everyone else Read access only, so they can view the file but not delete it.

This would be a good solution if you are worried about people deleting other users' work. Not good if your intentions for blocking delete actions are for archival purposes.

Author Closing Comment

ID: 31671310
Thank you experts for answering.  I knew that there is no 100% good answer here and unfortunately the separate folder for each user will not work (they need to share AND MODIFY the files between them)

I appreciate you time.  Thank you and Happy New Year

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Integration Management Part 2
Whether it be Exchange Server Crash Issues, Dirty Shutdown Errors or Failed to mount error, Stellar Phoenix Mailbox Exchange Recovery has always got your back. With the help of its easy to understand user interface and 3 simple steps recovery proced…

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question