Solved

Prevent users from moving/deleting folders on a 2008 file server

Posted on 2013-01-04
3
925 Views
Last Modified: 2013-01-16
Some of my users are a bit careless and accidentally drag/move folders to other locations on the file server. And there is the occasional deletion of folder trees.

Is there a simple way to keep users from moving or deleting folders?  There is seldom a need for a user to delete a folder.

Basically I'd like to set the permissions of the folder object to prevent a user from moving/deleting it, yet allow Modify access to the files within the folders.

- It's OK if users create new folders, but not delete them, or at least not delte those created by other users.  
- Users need Modify rights to the files in folders to create/view/edit/delete files.
- Domain Admins need to maintain rights to modify the folders.  

I looked through Advanced Permissions, but folder and file deletion seem bound to each other (Delete Subfolders and Files).

I have 500 users, The file server is running Server 2008 R2 Enterprise SP2. There is one share (GROUPS) with with numerous folders beneath (SALES, MARKETING, AP...) which each have different NTFS permissions set on them.
0
Comment
Question by:Justin S.
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 28

Expert Comment

by:jhyiesla
ID: 38743843
Yeah, I think you've pretty much answered your own question. MS has never had real granular permissions on files vs folders and the Advanced section is where I would have sent you, but you're right, files and folders are linked together.

We have this same problem, although it's not real bad and we basically just have to have a good back up of the server and be able to restore things that get deleted.
0
 

Author Comment

by:Justin S.
ID: 38744160
Perhaps. Maybe something in Group Policy or some magical reg edit? I'm hoping to be surprised...
0
 
LVL 28

Accepted Solution

by:
jhyiesla earned 500 total points
ID: 38744516
Although I don't know by heart all the registry keys or GPO settings, I'd not suspect you'd find something there. These tend to operate at the macro level meaning that you are changing things globally and not microscopically at the file or folder level. I can changes desktop behavior, but not the specifics of what's on the desktop, for example.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Dramatic changes are revolutionizing how we build and use technology. Every company is automating, digitizing, and modernizing operations. We need a better, more connected way to work together as teams so we can harness the insights from our system…
If you are IT support and need to work after hours to resolve customer issues then here are a few tips on how to handle after hours support
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question