Solved

Folder Permissions

Posted on 2013-12-04
10
270 Views
Last Modified: 2014-01-07
Hi,

We are trying to change the folder permissions on a client user profiles and for some unknown reason the permissions aren't filtering through to the sub folders - they can access to main parent folder but 2 folders down it says access denied.

When I add the user permission I am selecting the "replace all existing inherited permissions on all descendants...... but I still have this same problem.

Am I missing something really simple here, never had this problem before.

They are using Windows SBS 2008 and I am logged in as the domain administrator

thanks
Ryan
0
Comment
Question by:ryank85
  • 5
  • 5
10 Comments
 
LVL 37

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39697611
1st you need to take folder ownership through advanced NTFS security permissions, then you can flow required users reqquired access from top to bottom with replace option.

Mahesh
0
 

Author Comment

by:ryank85
ID: 39697619
Thanks. So I need to make sure the domain admin is the owner of the top level folder I.e 'userprofiles' or the folder below of the 'username'

Ryan
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39697652
Do not take ownership of folder at top level directly, or else it may wipe out other users permissions and granting you full control permissions
Then you need to go each subfolder (Profiles) and explicitly grant individual users permissions

Insstead you can take ownership of individual user profile folder and then grant user full control permission

If you could try MS tool subinacl to take ownership of userprofiles root folder, it might help as it will not wipe users permissions on sub folder

subinacl /subdirectories "C:\Userprofiles\*" /setowner=domain\domainuser

http://www.microsoft.com/en-in/download/details.aspx?id=23510
Mahesh
0
PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

 

Author Comment

by:ryank85
ID: 39697680
Thanks I will give this a go later. Much appreciated.

Ryan
0
 

Author Comment

by:ryank85
ID: 39698124
Hi,

when I run this command I get the following error -

subinacl /subdirectories "D:\UsersProfiles\john" /setowner=domain\administrator

'1337 The Security ID structure is invalid'

Error when checking arguments - D:\UsersProfiles\john


Ryan
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39698141
You need to add \ after directory otherwise it will give error

For Example:
subinacl /noverbose /subdirectories "D:\UsersProfiles\john\" /setowner=domain\administrator

OR

subinacl /noverbose /subdirectories "D:\UsersProfiles\john\*" /setowner=domain\administrator

Mahesh
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39698148
0
 

Author Comment

by:ryank85
ID: 39698168
Ok I have done that and the command now works, however when I re run the permissions on the root folder i.e. D:\UsersProfiles\john\ and select replace all existing permissions etc it still doesn't work.

e.g. when I go into the folder one level down - D:\UsersProfiles\john\documents and right click and look at the permissions it has John in the list however no ticks underneath saying he has any permissions
security.JPG
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39698222
can you check ownership of "John" Folder
The command will just give you ownership of folder to able to provide permissions
You need to give manual permissions

if its not reflected for your ID, then probably you need to run :

subinacl /noverbose /subdirectories "D:\UsersProfiles\*" /setowner=domain\administrator

This should work.
But it won't gurantee that it will not replace users permissions as well on the sub foders. Normally it don't, but we cannot gurantee it.
If sub folders are less and easily identifyable, then you can take risk.
If permissions got replaced with ownership, you can manually enforce permissions with replace option on sub folders with respective users

Mahesh

Mahesh
0
 

Author Closing Comment

by:ryank85
ID: 39761722
I also had to reset the permission of the level 2 folders.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many people use more than one email account and so it becomes difficult for them to manage them when they use separate accounts,  so, in this article, I have shared an easy way to add Other Mail Accounts in your Google Inbox. It helps to combine all…
In this step by step procedure, you will come to know the details of creating an Outlook meeting in 2007, 2010, 2013 & 2016.
CodeTwo Sync for iCloud (http://www.codetwo.com/sync-for-icloud?sts=6554) automatically synchronizes your Outlook 2016, 2013, 2010 or 2007 folders with iCloud folders available via iCloud Control Panel. This lets you automatically sync them with…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question