?
Solved

NTFS permissions issue

Posted on 2014-01-23
2
Medium Priority
?
265 Views
Last Modified: 2014-01-23
Hi I have a server with a folder that when users put files in it the files don't have the users group added to the permissions of that file only the creator and admin group  is added.  I have inherit permisisons turned off and tried it turned on and have the users group with full access to this folder.  When I manually "replace all child object permissions"  it does apply the users group to all files in this folder but when a new file gets created the user group is not part of the permissions of that newly created file.   Any idea on what I need to change  for permissions on this folder to allow the user group to be part of permissions on newly created files?

This is server 2008 R2.  No domain.
0
Comment
Question by:nologytech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 30

Accepted Solution

by:
Rich Weissler earned 1000 total points
ID: 39803994
Just to eliminate the 'easy' possibilities:
Confirm that you are creating a new file, and not copying/moving a file into the folder from another directory on the same volume.  (Just to make triple certain, open up notepad with a blank file, and safe the file in that directory... confirming that the expected permissions aren't being inherited.)  MS Office and other office productivity products are notorious for moving/renaming files (especially hidden files) rather than making new files.  In many cases, it to protect the contents... but it can make troubleshooting file permissions when the directory permissions are changing... challenging.

And it sounds like you've been making several changes to this folder permissions recently.  Take a step back... and test the behaviour in a different, unrelated folder.  Create a new empty folder with the permissions you want to be inherited, and try creating a new file there, and check to make certain it receives the permissions you expect.  

The good news is that it sounds like you're already approaching the problem well.  Unfortunately, that's also the bad news.  There's an assumption being made, or some piece of information missing.  If neither of the 'easy' approaches, I think you need a fresh set of eyes.  Again, two ways to get'em.  (1) Step away from the problem for an hour... get some food, and approach the problem as if someone brought the problem to you and start at the top and confirm all the assumptions.  (2) Option two, grab some screen shots and redact anything you don't want folks to see.  Start with the directory structure, and contents of the folder.  Then get the permissions screens.
0
 

Author Comment

by:nologytech
ID: 39804081
Thanks I disabled all inheritance and set the user group as owner and now its working.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question