Solved

Profile Security Permissons on Server 2008 for Folder Sync/Roaming

Posted on 2011-03-22
1
560 Views
Last Modified: 2012-05-11
Hey everyone,

I've recently setup a new DC with roaming profiles & folder synchronization (through group policy).

Everything is working great, when a new user logs in, it generates everything right away.. and I have it going to the following location .... \\SERVER1\Profiles\user

The only problem is, all the users are able to see eachothers Desktop, Documents, Favorites, etc...

Right now the seucirty is set to Everyone, it's the only way I could get it to work and write the permissions to all the files.. I tried going individually and changing each user folder with full access to their corresponding user name, and it didn't work..

On the Profiles (parent) folder here is what the security is set to presently..

Creator Owner > Subfolders and Files only
Authenticated Users > This folder only
Everyone > Full
SYSTEM > Full
Administrator > Full
Domain Admins > Full

What do I need to change it to so they can only view their personal folders? Will I need to go to each user folder and set it manually?
0
Comment
Question by:barbs1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 8

Accepted Solution

by:
ActiveDirectoryman earned 250 total points
ID: 35195161

1.  I would create a security group for users that have profiles in profiles folder and then limit access to just these users.

NTFS PERMISSIONS for parent folder should be:

Creator Owner -Full Control, Subfolders and Files Only
 Administrator-None
Security group of users needing to put data on share-List Folder/Read Data, Create Folders/Append Data - This Folder Only
Everyone-No permissions
Local System-Full Control, This Folder, Subfolders and Files

Share-Level Permissions should be:

Everyone-no permissions  
 
Security group of users needing to put data on share-Full Control
 
----

NTFS PERMISSIONS FOR EACH USER'S ROAMING PROFILE FOLDER

%username&-Full control, owner of folder
local system - full control
Administrators- no permissions ( this is the default unless the "Add the Administrator security group to the roaming user profile share) policy setting is set in which case administrators has full control
Everyone-no permissions

Security reccommendations for roaming user profiles shared folders
http://technet.microsoft.com/en-us/library/cc757013(WS.10).aspx
 
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question