Solved

Folder / File Permission settings - SBS2008

Posted on 2011-02-25
2
530 Views
Last Modified: 2012-05-11
Hello,

i have a rather simple question regarding assigning Sharing and Security permissions. Here is the scenario:

I have a main folder on the server drive, let call it:  WORK, 5 user need access to this folder including all sub folders and files in it.

Two of the user should be able to do anything they want, delete, change, create, etc.
The other three user should only be able to do changes on files within the folder, they should not be able to move or delete any files or sub folders within the WORK folder.

One of the user keep trying to create shortcuts of files withing the share and keeps moving them to his local machine. I am sure you guys know what i am talking about.

Thanks for your help!


0
Comment
Question by:Martin Gerlach
2 Comments
 
LVL 15

Accepted Solution

by:
markdmac earned 250 total points
ID: 34986733
Use groups to set permissions. Create groups, one for full control and the other for restricted access.

Modify the NTFS permissions of the folder by assigning the groups. Use the advanced settings to get granular.

You will not be able to do all that you are asking. A deletion is nothing more than a modify. So the restricted group can be given the right to create new files, but giving them modify will also let them move and delete.

Make sure you have ShadowCopy enabled so you can quickly revert the folder to a previous state if necessary.
0
 
LVL 62

Assisted Solution

by:btan
btan earned 250 total points
ID: 34990386
Ideally, the users are grouped into their work and privilege workgroup in AD hence the security can be applied as a group and ease the management (esp if user will to leave the organisation and the folder is EFS protected). But if the folder is temporary, and user access is only a small group and you intent to go granular per user basic, go for user names instead of group - but advisable not since it cannot be scalable for administration.

For the 2 users, give Full Control  
For the other 3 users, give Write, which is same as Read, plus the ability to change file content and attributes

If you want to go into granularity, it is under the special permission. But if to prevent copy (with still the given "Write" permission), it is not possible using only NTFS permission. But you can check out this link - http://www.instantfundas.com/2009/04/how-to-prevent-file-copying-deletion.html

Other note for considerations
- suggest turning on audit setting (object access) -  http://support.microsoft.com/kb/310399. There is equivalent at group policy level. In the event of breach, this may come in handy
- also if the permission is ported from NTFS to FAT the permission would break
0

Featured Post

Save on storage to protect fatherhood memories

You're the dad who has everything. This Father's Day, make sure your family memories are protected. My Passport Ultra has automatic backup and password protection to keep your cherished photos and videos safe. With up to 3TB, you have plenty of room to hold the adventures ahead.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

A procedure for exporting installed hotfix details of remote computers using powershell
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now