Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Folder / File Permission settings - SBS2008

Posted on 2011-02-25
2
Medium Priority
?
538 Views
Last Modified: 2012-05-11
Hello,

i have a rather simple question regarding assigning Sharing and Security permissions. Here is the scenario:

I have a main folder on the server drive, let call it:  WORK, 5 user need access to this folder including all sub folders and files in it.

Two of the user should be able to do anything they want, delete, change, create, etc.
The other three user should only be able to do changes on files within the folder, they should not be able to move or delete any files or sub folders within the WORK folder.

One of the user keep trying to create shortcuts of files withing the share and keeps moving them to his local machine. I am sure you guys know what i am talking about.

Thanks for your help!


0
Comment
Question by:Martin Gerlach
2 Comments
 
LVL 15

Accepted Solution

by:
markdmac earned 1000 total points
ID: 34986733
Use groups to set permissions. Create groups, one for full control and the other for restricted access.

Modify the NTFS permissions of the folder by assigning the groups. Use the advanced settings to get granular.

You will not be able to do all that you are asking. A deletion is nothing more than a modify. So the restricted group can be given the right to create new files, but giving them modify will also let them move and delete.

Make sure you have ShadowCopy enabled so you can quickly revert the folder to a previous state if necessary.
0
 
LVL 65

Assisted Solution

by:btan
btan earned 1000 total points
ID: 34990386
Ideally, the users are grouped into their work and privilege workgroup in AD hence the security can be applied as a group and ease the management (esp if user will to leave the organisation and the folder is EFS protected). But if the folder is temporary, and user access is only a small group and you intent to go granular per user basic, go for user names instead of group - but advisable not since it cannot be scalable for administration.

For the 2 users, give Full Control  
For the other 3 users, give Write, which is same as Read, plus the ability to change file content and attributes

If you want to go into granularity, it is under the special permission. But if to prevent copy (with still the given "Write" permission), it is not possible using only NTFS permission. But you can check out this link - http://www.instantfundas.com/2009/04/how-to-prevent-file-copying-deletion.html

Other note for considerations
- suggest turning on audit setting (object access) -  http://support.microsoft.com/kb/310399. There is equivalent at group policy level. In the event of breach, this may come in handy
- also if the permission is ported from NTFS to FAT the permission would break
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An overview of cyber security, cyber crime, and personal protection against hackers. Includes a brief summary of the Equifax breach and why everyone should be aware of it. Other subjects include: how cyber security has failed to advance with technol…
Phishing emails are a popular malware delivery vehicle for attack.  While there are many ways for an attacker to increase the chances of success for their phishing emails, one of the most effective methods involves spoofing the message to appear to …
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

963 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question