Solved

Apply changes to Active Dirctory

Posted on 2012-12-21
11
215 Views
Last Modified: 2012-12-31
I have a Windows 2008 r2 server.  We also have 2 terminal servers.  I did changes to file permissions and had the user log off the network and then log back in.  

He tells me if he access's the folder in question from his local desktop, he still cant access the folder.  BUT if he logs on the the terminal server, he CAN access the folder.

What did I do wrong OR how do I force it to apply so he can also access the network folder from his local desktop.
0
Comment
Question by:bankwest
11 Comments
 

Author Comment

by:bankwest
ID: 38713150
Forgot to mention.   To give this user the permissions he needs, I added him to a group in Active Directory Users and Computers
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 167 total points
ID: 38713173
use the effective permissions option to determine actual permissions - see http://technet.microsoft.com/en-us/library/cc756795(v=ws.10).aspx

also check both the SHARE and NTFS permissions
0
 
LVL 13

Expert Comment

by:upalakshitha
ID: 38713245
I think you have modified shared folder share permission to user. that is the reason he cannot access it from network.
when he access specified folder from TS session,I think he does it by opening local drives of server. so he does not need share permission for that.
if you have modify  NTFS permission incorrectly, TS session also cannot access folder
so you need to modify shared folder share permission i think
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38713255
He needs to be an ASD user and be joing to the domain for starters. After that is completed, verify his permisions are correct. Check his explidid permissions on that folder and verify he has read/write access.
0
 

Author Comment

by:bankwest
ID: 38713840
On my Network-data drive the Share permissions show Everyone with full control.   Then the NTFS permissions shows:
Domain Admins with full Control
Users (for our domain) with read, list and read & execute.

Then I go to the folder in question and the Group he is in has Modify, Read & Execute, List and Read

When I look at the effective permissions on that folder, that group has the correct permissions.

So I don't understand why he can't access the information from his local desktop but can from his TS desktop.

He is a user in Active Directory and is joined to our domain correctly and when I look at that folder and permissions...That group has correct permissions.  

Also, as a side note:   I thought in reading about permissions, that Share permissions and NTFS are independent of each other.    And one approach suggested is to set share permissions to full control on everyone (which I did) and rely on NTFS permissions to restict access.
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 333 total points
ID: 38714490
Hi.

You have to make clear if that resource is on a share of the TS or on another server. If on another server, the only possible explanation would be: the access token is assigned by a domain controller and the TS does not choose the same DC as the workstation does. So maybe the change in group membership has not replicated to that DC the workstation chooses. That would make it a replication problem.

See if the command
echo %logonserver%
produces the same result or not.
0
 

Author Comment

by:bankwest
ID: 38718918
McKnife

That command Produces same result for both.  (Our DC)
0
 
LVL 54

Expert Comment

by:McKnife
ID: 38721335
Hi and merry xmas!

You still did not make clear if that resource is on a share of the TS or on another Server. Please do so.
0
 

Author Comment

by:bankwest
ID: 38721357
Sorry......   Got side tracked.    I did the command above and as it should be, the resource is our primary domain controller.   Confirmed it both locally and thru TS login.    So, the share is on another server
0
 

Author Comment

by:bankwest
ID: 38721729
Thinking on this.   This is first time that I have set file permissions on a network.    So I am trying to be very cautious.  
Could this be my problem??
Let say John is a loan officer and needs modify/read/read execute on folder called LOAN

John is a member of the users group that has read and read/execute and is also a member of VP group that has modify, read and read/execute

Since he is a member of both groups will the settings for Users override settings for VP?
since they are more restrictive
0
 
LVL 54

Accepted Solution

by:
McKnife earned 333 total points
ID: 38723051
Permissions are additive. He'll have modify rights, then.
There's something fishy. You should do more tests with another share or even different shares on different servers to see if there are other irregular behaviors.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
AD and Exchnage 2010 Photos 3 42
Forest and doamin tree 3 26
Locate Source of Failed AD Authentication 7 21
Retrieve Active Directory Groups a User belongs to in VB.NET 3 20
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conneā€¦
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlleā€¦

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question