Why does a shared folder on my Windows 2003 server keep losing its assigned access rights?

Posted on 2011-04-27
Last Modified: 2012-08-13
Have been unsuccessful at trying to get logon scripts to work on my Windows 2003 domain through Group Policy. Using GPO editor I discovered that the Default Group Policy object was disabled and there was another group policy object that was apparently created to replace it.
I enabled the original and deleted the replacement. Now access to one of the shared folders has been lost to everyone execpt Administrators and when I try to add other users or groups they disappear after a couple of minutes. All other shares seem to be working okay, just this one is having a problem. Where should I be looking to fix this? Clients are Windows XP pro.
Question by:ru-rd
    LVL 37

    Accepted Solution

    It's possible the ACL for the folder is being modified by a GPO. Check your GPOs for settings in Computer Configuration\Windows Settings\Security Settings\File System.

    Author Comment

    As suggested I went to the shared folder through GPO and found only Administrators had access. I added the required group and so far it seems to be persisting. I will know tomorrow if the changes were retained overnight.
    LVL 37

    Expert Comment

    by:Adam Brown
    You'll need to run GPUpdate for the changes to take affect.
    LVL 4

    Expert Comment

    by:Vishal Patel
    Try to change NTFS security setting for that folder in align with your current sharing rights.
    You can do so by right clicking on folder and go to security and add users for the rights.

    Expert Comment

    make sure the GPO is not being skipped by another enforced GPO

    Author Closing Comment

    Thanks for your speedy solution! Obviously I have a lot to learn about GPO. Your service is definitely a valuable resource.

    Featured Post

    Do You Know the 4 Main Threat Actor Types?

    Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

    Join & Write a Comment

    [b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
    Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
    This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now