Solved

Profile Security Permissons on Server 2008 for Folder Sync/Roaming

Posted on 2011-03-22
1
555 Views
Last Modified: 2012-05-11
Hey everyone,

I've recently setup a new DC with roaming profiles & folder synchronization (through group policy).

Everything is working great, when a new user logs in, it generates everything right away.. and I have it going to the following location .... \\SERVER1\Profiles\user

The only problem is, all the users are able to see eachothers Desktop, Documents, Favorites, etc...

Right now the seucirty is set to Everyone, it's the only way I could get it to work and write the permissions to all the files.. I tried going individually and changing each user folder with full access to their corresponding user name, and it didn't work..

On the Profiles (parent) folder here is what the security is set to presently..

Creator Owner > Subfolders and Files only
Authenticated Users > This folder only
Everyone > Full
SYSTEM > Full
Administrator > Full
Domain Admins > Full

What do I need to change it to so they can only view their personal folders? Will I need to go to each user folder and set it manually?
0
Comment
Question by:barbs1
1 Comment
 
LVL 8

Accepted Solution

by:
ActiveDirectoryman earned 250 total points
ID: 35195161

1.  I would create a security group for users that have profiles in profiles folder and then limit access to just these users.

NTFS PERMISSIONS for parent folder should be:

Creator Owner -Full Control, Subfolders and Files Only
 Administrator-None
Security group of users needing to put data on share-List Folder/Read Data, Create Folders/Append Data - This Folder Only
Everyone-No permissions
Local System-Full Control, This Folder, Subfolders and Files

Share-Level Permissions should be:

Everyone-no permissions  
 
Security group of users needing to put data on share-Full Control
 
----

NTFS PERMISSIONS FOR EACH USER'S ROAMING PROFILE FOLDER

%username&-Full control, owner of folder
local system - full control
Administrators- no permissions ( this is the default unless the "Add the Administrator security group to the roaming user profile share) policy setting is set in which case administrators has full control
Everyone-no permissions

Security reccommendations for roaming user profiles shared folders
http://technet.microsoft.com/en-us/library/cc757013(WS.10).aspx
 
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question