Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Folder security in Active Directory

Posted on 2012-04-12
4
Medium Priority
?
528 Views
Last Modified: 2012-04-30
I have a user that needs access to a subfolder on our shared drive.  I just want her to have access to the subfolder not the anything north of the folder.  Right now I have her added to the subfolder security and not inheriting permissions.  She can't access the folder.  Any help would be greatly appreciated.

Thanks,
snip.PNG
0
Comment
Question by:bhiller06
4 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 500 total points
ID: 37840926
This can be tricky, you want the traverse folder permission in the advanced security: http://www.techrepublic.com/article/windows-101-know-the-basics-about-ntfs-permissions/6084446
Share and NTFS permissions work in tandem, and they will take the most restrictive permission as it's action, so even if the user is allowed in the NTFS permissions, if they are denied in the share permission's then that will be the action taken. Share permissions are much less verbose than NTFS, and NTFS is where you should be applying most restrictions or permissions to keep things simple, and in case someone also has the logon interactively permission, they can just go straight to that folder if the share permissions are what is keeping them out on the network. Apply most if not all restrictions at the NTFS level.
-rich
0
 
LVL 22

Assisted Solution

by:chakko
chakko earned 500 total points
ID: 37841191
Have you tried to access the folder directly such as \\server\share\folder\subfolder-you-want

or try to map a drive letter using the long/deep path  like;  net use x: \\server\share\folder\subfoler-you-want

and as richrumble already stated, make sure the permissions are not blocking access.
0
 
LVL 24

Assisted Solution

by:Mike Thomas
Mike Thomas earned 500 total points
ID: 37841372
As chakkapo says it might be best to direct her straight into the desired subfolder, maybe with a new share just for that purpose, but if you want to do it the regular way then just just needs to list and traverse all folders above.

And make sure the share permissions are in order not just NTFS.
0
 
LVL 29

Assisted Solution

by:pwindell
pwindell earned 500 total points
ID: 37842778
Forget Drive Letters and "mapping".  The 1990's are over and this isn't Novell

Go directly to the Folder via the Path as Chakko is saying.  \\server\share\folder\subfolder-you-want

It also is not all about Share Permissions.  It is about both Share and NTFS Permissions,...they are two different things.  The Share that the user is comming "though" must allow them Read or Read/Change,...the NTFS Security then have to control it from there.   This stuff can get really complex if you get too picky and complicated about what you want of expect.
0

Featured Post

Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question