Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

group access to shared folder

Posted on 2012-03-23
7
Medium Priority
?
462 Views
Last Modified: 2012-04-08
Hello,

I have setup a shares for the following:

d:\share = \\server\share

All users have read access.

I have setup groups to provide different access.

d:\share\department1  - dept1 can have full control, all others can read only
d:\share\department2 - dept2 can have full control, all others can read only

How can I provide one share so I change access by groups for different folders?
0
Comment
Question by:tucktech
7 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 37758947
You can give them full control via share and then you can use NTFS permissions on the folder (right click on the folder and then the security tab)

So you setup dept1 the way you described and then dept2.  
Thanks

Mike
0
 

Author Comment

by:tucktech
ID: 37759003
I did this and they the group I tested had full control in the root directory and every directory of the share.

More specifically I gave read/write share control to all users.  I had already changed the security access availalbe at the sub folder levels.

Rather than giving full control to everyone should I list the groups individually in the share?
0
 
LVL 7

Expert Comment

by:hirenvmajithiya
ID: 37761948
As share permission and NTFS permission takes effect back to back, you can give full access to everyone one \\server\share folder and then in NTFS you assign permission as you need.

Hiren
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 1

Expert Comment

by:mbm2708
ID: 37775136
hi man

simple

you create 2 groups dep1 and dep 2  put the user on the right group dont forget setup the group as security group and global group

go to the share management and click on the propriets of department1 and add the group dep1 and put as full permission and everyone as read permission
the same to the department2



thank you
0
 

Author Comment

by:tucktech
ID: 37798015
None of this is working as I would think. Let me explain further and you may be able to see my error in applying the access.

Everyone has use of the share drive via an s: drive.  In other words, if I were to setup from the command prompt.  I would type net use s: \\server\share.  Everyone has this same "use" statement.

What I wanted to do was for everyone to have the same "s" drive and to control access via groups.  Via the share from the server (and note I am using DFS). I provided everyone read access.  Then I went, on the server, and allowed specific group access to their folder.  My results was that when i logged in as a member of a share that should have had access, I got access denied when I tried to create a folder.

When I went back and provided full control for the share with a specific group, that allowed full control regardless of the NTFS security.

It appears share overrules NTFS security.

Help....
0
 

Accepted Solution

by:
tucktech earned 0 total points
ID: 37803219
AHH HA!  I figured it out.

ON the root share directory I had to remove the "Include inheritable permissions from this object's parent" found in the folders Properties | Security | Advanced.

Once I did this it all came together.
0
 

Author Closing Comment

by:tucktech
ID: 37820901
I had already understood what the other comments provided.  Once I went back and read through how the permissions work for Server 2008, etc.. I found that I did NOT want inheratence for the root object.  Once I did this it worked.  None of the answers were wrong they just did not include this required piece of information to fix my concern.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question