?
Solved

Clean Up Active Directory Permissions SBS 2003

Posted on 2010-11-15
5
Medium Priority
?
346 Views
Last Modified: 2012-05-10
I have an SBS 2003 server, we have a bunch of shared folders. I need to change permissions on these folders. All users are seperated into 2 groups, Staff, Interns. Staff should have access to almost all of the folders, there are 1 or 2 folders only certain staff members should have access to. Interns should have very limited access to a couple folders. I am not sure who initially set all this up but when I look at the permissions of a folder it is a huge mess. Usually on any given folder it has the staff group, interns group, individual users, and lots of "account unknown", etc... Does anyone know how I can maybe wipe out all of the old permissions and start from scratch? Or any other suggestions. Help is very much appreciated. Thanks
0
Comment
Question by:lgg733
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 35

Accepted Solution

by:
Joseph Daly earned 1200 total points
ID: 34141488
If you want to wipe out ther permissions for all the folders you should be able to go to the top folder and then apply the desired settings you want and then select the option to replace the permissions on all child folders.

Be very careful with this because if you are not sure what you are doing you can cause yourself a whole lot of headache.  security
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 800 total points
ID: 34143658
0
 
LVL 4

Author Comment

by:lgg733
ID: 34145415
Thanks for the help I will look your suggestions over asap. What about the "account unknown"s can I get rid of those?
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 34145518
How do they appear in the permissions listing? Do they show as S-1-xxxxxxxxxxx.

If so those are user accounts that are no longer present in AD and should be safe to be removed.
0
 
LVL 4

Author Comment

by:lgg733
ID: 34145649
Yes they do appear like that, I will try and delete them.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question