Solved

File Server Permission

Posted on 2013-01-09
8
23 Views
Last Modified: 2016-01-14
I have an issue with assigning rights to sub folders on our file server.
 
I want to add access to a user on a shared folder and want that user to have permissions to all sub folders. The sub folders however are set to not inherit permissions from the parent folder so the permission change on the shared folder doesn't affect the sub folders.

Please let me know if there is a way to easily give permissions to the sub folders, without setting permissions for each sub folder.
0
Comment
Question by:aditp
8 Comments
 
LVL 14

Expert Comment

by:BlueCompute
ID: 38758472
You can force inheriting of permissions from the Advanced Security Settings of the parent folder.  If you check the box 'replace all child object permissions with inheritable permissions from this object' then it forces replacement of the permissions on the sub-folders, even if they are set to not inherit inheritable permissions from their parent folders.
0
 

Author Comment

by:aditp
ID: 38773405
As explained , 'replace all child object permissions with inheritable permissions from this object' will force all child folders to have same permissions as the parent folder. In which case all exclusive permissions set on all child folders will be lost. So this option will not work
0
 
LVL 16

Assisted Solution

by:Syed_M_Usman
Syed_M_Usman earned 50 total points
ID: 38826259
Dear,

i would suggest to spare few minutes and read WHAT MICROSOFT RECOMENDS on the same,

Best practices for permissions and user rights:http://technet.microsoft.com/en-us/library/cc779601(WS.10).aspx

&

Best practices for Shared Folders:http://technet.microsoft.com/en-us/library/cc780313(WS.10).aspx

i would suggets below;

1) Logon to your DC, and create two Groups
a----Domain Local Group DL_Modify_xyz
b----Global Group G_Modify_Tech
c----Click on Global Group and Go to Member of and add DL_Modify_xyz
4---Click on Global Group and Go to Members and add all users you ask in question

2) logon to server where folder exist
a------Right Click Take Folder Properies>Sharing>Advance Sharing
b------Click on share this folder
c-------Click on permissoons--->
UNCHECK------Everyone from the list
ADD-----> type DL_Modify_xyz and click check names.. you will find DL_Modify_xyz group, click ok and finish
now on permission TAB, click on Read and Change.......ok ok

3)Right Click Take Folder Properies>Security TAB
click on DL_Modify_xyz and click ADVANCED ,,, NOw click on DL_Modify_xyz and click change permission.....

Now you can assign any persimmon you want....
0
 
LVL 25

Accepted Solution

by:
Coralon earned 50 total points
ID: 38827448
Without inherited permissions, you will *have* to assign the permissions to each subfolder.  However, from a command line, this is not a daunting task.  

From a command line, browse to the parent directory.  Assuming you want to give the users Modify access, it would be something like this:

cd d:\parentdir
for /d %f in (*) do cacls /e /g /t "domain\new group":c "%f"

Open in new window


If you don't want to do all of them, you have other options..

If you only have a few directories, it would be:
cd d:\parentdir
for /d %f in (subdir1 subdir2 subdir3) do cacls /e /t /g "domain\new group":c "%f"

Open in new window


If you have a lot of directories, you can create a text file with the correct directories in it.  Assuming the file is called dirs.txt, and you just have one directory name per line on it.
cd d:\parentdir
for /f %f in (dirs.txt) do cacls /e /t /g "domain\new group":c "%f"

Open in new window


Coralon
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADFS Setup 4 40
Need help Creating a Powershell script 8 51
DC dynamic port change? 1 16
how to demote a DC microsoft server 2016 13 31
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question