Solved

Clean Up Active Directory Permissions SBS 2003

Posted on 2010-11-15
5
321 Views
Last Modified: 2012-05-10
I have an SBS 2003 server, we have a bunch of shared folders. I need to change permissions on these folders. All users are seperated into 2 groups, Staff, Interns. Staff should have access to almost all of the folders, there are 1 or 2 folders only certain staff members should have access to. Interns should have very limited access to a couple folders. I am not sure who initially set all this up but when I look at the permissions of a folder it is a huge mess. Usually on any given folder it has the staff group, interns group, individual users, and lots of "account unknown", etc... Does anyone know how I can maybe wipe out all of the old permissions and start from scratch? Or any other suggestions. Help is very much appreciated. Thanks
0
Comment
Question by:lgg733
  • 2
  • 2
5 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 300 total points
ID: 34141488
If you want to wipe out ther permissions for all the folders you should be able to go to the top folder and then apply the desired settings you want and then select the option to replace the permissions on all child folders.

Be very careful with this because if you are not sure what you are doing you can cause yourself a whole lot of headache.  security
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 200 total points
ID: 34143658
0
 
LVL 4

Author Comment

by:lgg733
ID: 34145415
Thanks for the help I will look your suggestions over asap. What about the "account unknown"s can I get rid of those?
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 34145518
How do they appear in the permissions listing? Do they show as S-1-xxxxxxxxxxx.

If so those are user accounts that are no longer present in AD and should be safe to be removed.
0
 
LVL 4

Author Comment

by:lgg733
ID: 34145649
Yes they do appear like that, I will try and delete them.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now