Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


List of user having access to each individual folder

Posted on 2013-10-31
Medium Priority
Last Modified: 2013-11-07
Hello experts,

I want to know user/ad access for all list folders in one dir.


path                                                            user\ad group having access
c:\temp                                                      domain\vivek
c:\temp\sub folder                                 domain\VIVEK,DOMAIN\AD GROUP1,AD GROUP2
c:\temp\sub folder2                               domain\sam,domain\vivek

And it should resurcive check all folders and should remove all users\ad group except DOMAIN\vivek,DOMAIN\sam
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Author Comment

ID: 39621208
Kindly look into this request.
LVL 43

Expert Comment

by:Steve Knight
ID: 39622406
Every single file can have different additional permissions and different owner aswell as inheriting from parent directory, or copy of the parent permissions and amended at will.

Would you not be better just pushing the permissions that you do want down from the top of that level?

i.e. in this case from GUI pov you select top level folder, select your two names (and presumably administrators/system at least right?) and replace permissions on sub folders and files.  If you don't have rights to some then take ownership first.

LVL 38

Expert Comment

by:Jim P.
ID: 39623279
You can use icacls (Win7/2008) or CACLS (Win2003/XP ) to get the info.

The recursion into the subdirectories is a different issue, that I don't know how to do in VBS and where or how to write it out.

C:\>icacls c:\temp
c:\temp BUILTIN\Administrators:(I)(F)
        NT AUTHORITY\Authenticated Users:(I)(M)
        NT AUTHORITY\Authenticated Users:(I)(OI)(CI)(IO)(M)

Successfully processed 1 files; Failed processing 0 files

Open in new window

LVL 25

Accepted Solution

Coralon earned 2000 total points
ID: 39623313
I would just use AccessEnum from Sysinternals.


Featured Post

Ready for your healthcare security check-up?

In the past few years, healthcare organizations have become a prime target for advanced attacks. Does your organization have what it needs to defend itself? Schedule your healthcare security check-up today and download our free Healthcare Security Resource Kit today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question