Setting Permission

I have a SHARE folder on SBS2011 where the group name "STAFF" has FULL ACCESS. The "STAFF" includes most domain users. The SHARE folder has many sub-folders. Today one of the users asked me if I can set the permissions on a specific sub-folder (under SHARE) so that some users would have FULL access where some has READ only access.
However all the users belong to the group "STAFF".
To be specific, say there are User1, User2, User3 and User4 that are members of the group "STAFF". The STAFF group has full access to D:\SHARE and its sub-folders. Now I need to set the permission on D:\SHARE\SubDir1\SubDir2\...\VacationLog folder so that User1 and User2 have Full Access whereas User3 and User4 have Read-Only access.
Yesterday I attempted, but was not successful.
Can you help?
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
Create a group called Read Access and place User 3 and User 4 in that group.   Apply Read access to SubDIR1

Although User3 and 4 are in both groups the most restrictive permissions win so they will only have read and those only in staff will still have full.

User 3 and 4 will have to log off and log back in after you add them to the new group.



Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
sgleeAuthor Commented:
I will try that and post the result.
Guy Hengel [angelIII / a3]Billing EngineerCommented:
put user3 and user4 into a new group.
in the VacationLog folder, set that group to have a "Deny Write" permission.

note that the user3/4 may need to log in again in order that they get that new group membershop permissions ...
Your Guide to Achieving IT Business Success

The IT Service Excellence Tool Kit has best practices to keep your clients happy and business booming. Inside, you’ll find everything you need to increase client satisfaction and retention, become more competitive, and increase your overall success.

sgleeAuthor Commented:
 After creating a new group "VacationReadUsers", I added the new group to Vacation folder with read/list permissions only, but I was able to change the contents of EXCEL file and save it.

  I will try "DENY" option as Guy Hengel suggested.
Mike KlineCommented:
Guy is right, sorry  I was thinking of share and NTFS permissions for most restrictive.  These are all NTFS.


sgleeAuthor Commented:
Permission PropertiesAfter adding "Write Deny" as Guy Hengel suggested, it worked.

Now I did not think of this: The group "STAFF" currently pretty much includes every domain users and not everyone should be able to make changes to the files in this folder.
If I want to allow only handful/selected users to have WRITE permission on this folder, what is the best way to accomplish that given the fact that STAFF group includes everyone pretty much and that group currently has full permission on VACATION folder.
Mike KlineCommented:
On that particular folder you could make Staff only have read and then create a write group and give them write permissions.


Guy Hengel [angelIII / a3]Billing EngineerCommented:
then you do this:
* create a new group VACATION_LOG, and grant read+write on that folder to that group
* add user1 and user2 to that group
* specify for the STAFF folder thant WRITE permissions are removed, and not inherited

the risk is that if at some point someone is reapplying the permissions from root folder to subfolders, this may get lost
sgleeAuthor Commented:
Security WarningAfter creating a new group "VacationWriteUsers" giving FULL Permission to User 1 and User2, I wanted to take out WRITE permission from STAFF folder.
So I went to "Advanced" and chose "Change Permission" for STAFF and when I uncheck the checkbox for "Include inheritable permission from this object's parent", I get this warning.
Guy Hengel [angelIII / a3]Billing EngineerCommented:
this is exactly what you want to achieve: this folder will NOT inherit any permissions you set at a higher level
Mike KlineCommented:
Click add on that dialogue box, then you can go in and change the staff permission.


sgleeAuthor Commented:
After "unchecking" the checkbox, now I am free to set permission level to STAFF group.
I removed Full Control/Modify/Write permissions.

Thank you for your help.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.