?
Solved

NTFS Folder Permissions

Posted on 2014-02-24
3
Medium Priority
?
467 Views
Last Modified: 2014-02-26
Had a request from a user to have the global downloads folder turned into a secure zone.

Basically need it so everyone can save to it, open their own files, but cannot view anyone elses files.

I have the following permissions in place.

Creator Owner - Full Control
Domain users - Write + List folder contents

The users don't want each other to be able to see the list folder contents but if I remove this it comes up access denied for the entire folder.

The only workaround I have thought of is to create a folder per user within downloads and tie it down so each person has their own folder which only they can view and save into.

But this has been met with "Why do I have to do this, I don't currently choose where I save my downloads will I have to manually move them into my folder everytime, will every staff member have to have their own folder."
0
Comment
Question by:GordonRae
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 3

Expert Comment

by:RKnebel512
ID: 39884591
Is this a single, communal computer you are talking about?  Or is it a shared drive on the network?
0
 

Author Comment

by:GordonRae
ID: 39884905
It's a domain

With a redirected my documents that points to one folder on the server.

Inside this share everyone has full control and domain users have full control on security

Inside this share there is a downloads folder which I have removed inheritance from and manually put in creator owner with full control and domain users with write and list folder contents

But the users don't want to be able to see all the list folder contents but when I remove list folder contents they cannot access the downloads folder it says access is denied
0
 
LVL 3

Accepted Solution

by:
RKnebel512 earned 1500 total points
ID: 39885520
I would create a home directory for each user. You would give each person their own folder.  

- Open up "Active Directory Users and Computers"
- Select all the users
- Right-click and chose properties.
- Go to the profile tab.
- Click the Home Folder check box.
- Select a drive letter.
- In the box put, "\\bigfirm.com\BigFirmShares\Home\%Username%"  (Replace the path with the real path of where these folders will be, but keep the "%Username%".  That will tell windows to just take the username and name the folder that)

This will be much easier to manage permissions.

As to the users not wanting to change where they are saving things, you can change the default to where it will be saved.  I'm sure there are scripts out there to automate it as well.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Learn about cloud computing and its benefits for small business owners.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question