Solved

Folder and File Permissions:  AD Security Group

Posted on 2011-03-01
4
884 Views
Last Modified: 2012-05-11
Hi Guys,

I have a network folder shared between a group of users.
When I give permissions to the group on the network folder, the users can only see the folders, but are unable to open documents from the network shared folder.  "Access Denied".

However, when I give permissions to the user-accounts directly on the shared-folder, the users can access all containing files and sub-folders without a problem.

I must be doing something wrong in the group-setup ... It is setup as a global security group with all users added as members within the group.

Having a group with all members will make life much easier than to add each individual user account to the shared folders.
0
Comment
Question by:Rupert Eghardt
  • 2
  • 2
4 Comments
 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 35006065
Is the user already a member of the group or are you adding the user to this group when you assign permissions? If you are adding the user to the group the user will need to logg off the computer then log back on before they get the new security token and can access the resource.
0
 

Author Comment

by:Rupert Eghardt
ID: 35006091
All users were assigned to the group.
I then assigned the rights to the shared-folder, and added the group to the permissions section of the folder - full control.

The user logged off / even restarted their W/S, but still "access denied".
However, when I add the user directly to the shared folder permissions, the user immediately has full rights.
0
 
LVL 27

Expert Comment

by:KenMcF
ID: 35006147
So you are adding the users and groups to the share? What about the NTFS permissions?
Usually when I setup a share I will give either everyone or authenticated users full control of the share permissions and then restrict using NTFS permissions.
0
 

Author Comment

by:Rupert Eghardt
ID: 35006345
Thanks for your help, I think I found the problem,

Under the shared-folder security tab, advanced, edit
I added the group with full control rights, BUT I CHECKED the "apply these permissions to objects and/or containers within this containers only".

I am sure this was the problem, I added the group again and didn't checked the box, seems to be working now ...
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
With the withdrawal of support for Windows Server 2003 this summer, many clients face the issue of moving away from their 2003 installs. There are a few options out there that many people/companies are selling. But the clients I have, haven't wanted…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now