• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 541
  • Last Modified:

Folder / File Permission settings - SBS2008

Hello,

i have a rather simple question regarding assigning Sharing and Security permissions. Here is the scenario:

I have a main folder on the server drive, let call it:  WORK, 5 user need access to this folder including all sub folders and files in it.

Two of the user should be able to do anything they want, delete, change, create, etc.
The other three user should only be able to do changes on files within the folder, they should not be able to move or delete any files or sub folders within the WORK folder.

One of the user keep trying to create shortcuts of files withing the share and keeps moving them to his local machine. I am sure you guys know what i am talking about.

Thanks for your help!


0
Martin Gerlach
Asked:
Martin Gerlach
2 Solutions
 
markdmacCommented:
Use groups to set permissions. Create groups, one for full control and the other for restricted access.

Modify the NTFS permissions of the folder by assigning the groups. Use the advanced settings to get granular.

You will not be able to do all that you are asking. A deletion is nothing more than a modify. So the restricted group can be given the right to create new files, but giving them modify will also let them move and delete.

Make sure you have ShadowCopy enabled so you can quickly revert the folder to a previous state if necessary.
0
 
btanExec ConsultantCommented:
Ideally, the users are grouped into their work and privilege workgroup in AD hence the security can be applied as a group and ease the management (esp if user will to leave the organisation and the folder is EFS protected). But if the folder is temporary, and user access is only a small group and you intent to go granular per user basic, go for user names instead of group - but advisable not since it cannot be scalable for administration.

For the 2 users, give Full Control  
For the other 3 users, give Write, which is same as Read, plus the ability to change file content and attributes

If you want to go into granularity, it is under the special permission. But if to prevent copy (with still the given "Write" permission), it is not possible using only NTFS permission. But you can check out this link - http://www.instantfundas.com/2009/04/how-to-prevent-file-copying-deletion.html

Other note for considerations
- suggest turning on audit setting (object access) -  http://support.microsoft.com/kb/310399. There is equivalent at group policy level. In the event of breach, this may come in handy
- also if the permission is ported from NTFS to FAT the permission would break
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now