• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 566
  • Last Modified:

Profile Security Permissons on Server 2008 for Folder Sync/Roaming

Hey everyone,

I've recently setup a new DC with roaming profiles & folder synchronization (through group policy).

Everything is working great, when a new user logs in, it generates everything right away.. and I have it going to the following location .... \\SERVER1\Profiles\user

The only problem is, all the users are able to see eachothers Desktop, Documents, Favorites, etc...

Right now the seucirty is set to Everyone, it's the only way I could get it to work and write the permissions to all the files.. I tried going individually and changing each user folder with full access to their corresponding user name, and it didn't work..

On the Profiles (parent) folder here is what the security is set to presently..

Creator Owner > Subfolders and Files only
Authenticated Users > This folder only
Everyone > Full
SYSTEM > Full
Administrator > Full
Domain Admins > Full

What do I need to change it to so they can only view their personal folders? Will I need to go to each user folder and set it manually?
0
barbs1
Asked:
barbs1
1 Solution
 
ActiveDirectorymanCommented:

1.  I would create a security group for users that have profiles in profiles folder and then limit access to just these users.

NTFS PERMISSIONS for parent folder should be:

Creator Owner -Full Control, Subfolders and Files Only
 Administrator-None
Security group of users needing to put data on share-List Folder/Read Data, Create Folders/Append Data - This Folder Only
Everyone-No permissions
Local System-Full Control, This Folder, Subfolders and Files

Share-Level Permissions should be:

Everyone-no permissions  
 
Security group of users needing to put data on share-Full Control
 
----

NTFS PERMISSIONS FOR EACH USER'S ROAMING PROFILE FOLDER

%username&-Full control, owner of folder
local system - full control
Administrators- no permissions ( this is the default unless the "Add the Administrator security group to the roaming user profile share) policy setting is set in which case administrators has full control
Everyone-no permissions

Security reccommendations for roaming user profiles shared folders
http://technet.microsoft.com/en-us/library/cc757013(WS.10).aspx
 
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now