Solved

share ACL only set at one level

Posted on 2013-06-10
3
482 Views
Last Modified: 2013-06-10
Am I right in thinking share access control permissions are only set at one level? Whereas NTFS are set at every directory level (albeit they can inherit).

And part 2) am I right in thinking if a user or group is NOT listed on share permissions (ACL), regardless of whether they are on NTFS (directory ACL) they cant access data on the directories on that share, i.e. you need to be on both the share and directory ACL?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 55

Accepted Solution

by:
McKnife earned 500 total points
ID: 39234197
Both right. Share permissions are for the share, not for the folders below. 2nd is right because the principle behind it is "effective is what is more restrictive"
0
 
LVL 3

Author Comment

by:pma111
ID: 39234257
I assume windows effective permissions feature, i.e.:

http://www.techotopia.com/images/5/51/Windows_server_2008_effective_permissions.jpg

Is only taking into consideration NTFS (directory permissions) and completely ignores share permissions?
0
 
LVL 55

Expert Comment

by:McKnife
ID: 39234267
Correct.
0

Featured Post

Enroll in June's Course of the Month

June's Course of the Month is now available! Every 10 seconds, a consumer gets hit with ransomware. Refresh your knowledge of ransomware best practices by enrolling in this month's complimentary course for Premium Members, Team Accounts, and Qualified Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to install and use the NTBackup utility that comes with Windows Server.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question