Solved

Revoke Permissions for creator owner on files Only

Posted on 2013-11-26
14
744 Views
Last Modified: 2014-01-15
I have a folder structure in place with parent and subfolders. I need to run a script so that it will revoke the permissions of the user who created it for files only.

i.e. If a User copies a file to the folder the write permissions for the file regardless of the name should be revoked.

Can the SUBINACL command do this?
0
Comment
Question by:GulfIT
  • 4
  • 4
  • 2
  • +4
14 Comments
 
LVL 11

Expert Comment

by:Gregory Miller
ID: 39677400
Would it be easier to have a script that changes the ownership of all files in the folder in a scheduled process? This way the complexities of allowing someone to create but not write but still read without modify... etc... do not exist. Sounds very messy and hard to troubleshoot.
0
 
LVL 9

Expert Comment

by:VirastaR
ID: 39677455
0
 

Author Comment

by:GulfIT
ID: 39677495
Further on this i have found the subinacl command with the filesonly switch but it does not remove permissions from the subfolders.

Is there a command to revoke permissions from all the files in the directory structure?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 39677598
Take ownership of all folders and subfolders and add desired permissions using standard ACL.
0
 
LVL 34

Expert Comment

by:Dan Craciun
ID: 39677682
Create the desired permissions on a file that you will use as template. Then use the following in powershell:

$path = "\path\to\files"
$template = "\path\to\template"
$templateACL = Get-Acl $template

$fileInfo = Get-ChildItem -path $path -Recurse:1 -file
foreach ($i in $fileInfo.fullname) {Set-Acl $i $templateACL}


Replace "\path\to\files" and "\path\to\template" with actual paths.

This will copy permissions from the template to all the files inside that folder, and only to files.

HTH,
Dan
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39677798
You need to replace Full control NTFS permissions with modify for all users and groups on the ACL except administrators.
Then You can remove "Creator owner" group with advanced NTFS permissions with replace option of folder root to remove owner of all files probably.

Once you remove "creator owner" group, then from next time user will not be able to take ownership and full rights of files

Mahesh
0
 
LVL 54

Accepted Solution

by:
McKnife earned 500 total points
ID: 39682487
No script needed. Simply setup NTFS permissions correctly:
For the user or user group, check the following boxes:
Screenshot
--However, all this will have no meaning, if we wouldn't set the share permissions to everyone:change (instead of everyone:full) as well!--
0
 

Author Comment

by:GulfIT
ID: 39682762
I need to revoke the permissions so that there even cannot write to the file. Thus a script running every night will need to take place.

The whole idea is the remove the write permissions to files that a perticular group is creating but these need to apply only to files not folders.
0
 
LVL 54

Expert Comment

by:McKnife
ID: 39683030
I know - I showed you how to set it up - it's tested. No need for a script.
If you are not satisfied, you can change the settings to "apply to files only"
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39683065
What you can do setup new shared folder with administrators full control and authenticated users Change share permissions.You should be logged on with account having administrators rights on server.

Now you need to go to NTFS security and 1st you need to remove inheritence on folder and then remove all users and groups including system, creator owner and so on.
Then add server\administrators with full control and authenticated users with read+write NTFS permissions on the folder and click apply.
Now edit advanced security permissions, revoke write attributes and write extended attributes from authenticated users and click apply.
Mcknife is correct, only you need to revoke above two permissions in addition as mentioned above.

Now users need to work on their document stored on their desktop and once they copied it to share folder, their access to that document will get revoke automatically
They cannot rename or edit the document.
Only they can read the document.They even can't overwrite the new document with same name

This is what I think you are looking for.
This is tested and working fine

Mahesh
0
 

Author Comment

by:GulfIT
ID: 39689213
Thanks for the update. I have applied the same permissions but cannot rename the folders.
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39689275
I don't understand what you are saying ?

Do you want to rename the folder ?

Once you revoke write attributes and write extended attributes from folder root, you cannot rename \ overwrite \ modify files and folder.
User need to work on documents on their desktop \ workstations and then they only can copy the document in shared folder
Once document gets copied there, all their rights will get revoked except read.

If I am not wrong, this is what you are trying to achieve
Lets share you requirement please if you are not agreed with above

Mahesh
0
 

Author Closing Comment

by:GulfIT
ID: 39781574
Done
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39781715
Still not get any reply as what you are looking exactly for ?
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question