?
Solved

Active Directory Folder security change

Posted on 2014-02-26
9
Medium Priority
?
175 Views
Last Modified: 2014-03-12
Setup a new folder with security rights for only specific individuals.

For one of the allowed users he cannot access the folder on his current workstation, but if the he logs into another workstation or into Terminal Services server session, he can access the folder and has all the rights he should have. It is just on his personal workstation that he cannot access the folder.

Rebooted, logged him back in and still no access.
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
  • 2
9 Comments
 
LVL 70

Expert Comment

by:KCTS
ID: 39890471
Sounds like an issue with the SHARE permissions - check these as well as NTFS
0
 

Author Comment

by:haradaindustryofamerica
ID: 39890489
I see no issues with either. He can log into any other machine on our network and access the folder fine, only his machine has problem accessing.
0
 
LVL 70

Expert Comment

by:KCTS
ID: 39890504
Check that the computer in question is authenticating to the network OK. It may have an issue and is logging on the user using cached credentials.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 37

Expert Comment

by:Mahesh
ID: 39893069
just remove affected machine from domain once and re-join to domain and try

On affected computer please open Advanced Tcp/IP settings and check DNS Tab.
In DNS tab, check below settings.
ensure that "Append Primary and connection specific dns suffixes" radio button is selected
Ensure that "Append parent suffixes of primary dns suffix" checkbox is selected
Ensure that "register this connection addresses in Dns" checkbox is selected
If there is any deviation in the above settings, its probably you will face name resolution and network access issues

Mahesh
0
 

Author Comment

by:haradaindustryofamerica
ID: 39900751
Mahesh -

Tried removing and adding back to domain, still has issue.

All the settings you referenced above were set already.

We had another user in his department with the same access rights as him log into his machine, they can access the folder fine. This is very weird.
0
 

Author Comment

by:haradaindustryofamerica
ID: 39907680
Does anyone have any other ideas?

Thanks in advance.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 39908541
Run rsop.msc on the affected machine and check if any specific policy denying that machine from accessing network shares ?
Also check if you can access any other share folders on other servers from this machine ?

Also check if you can access netlogon and sysvol share folders on domain controllers

Go to run and enter %logonserver%
This should resolve to NetBIOS name of its local authenticating DC
if here you get error or it resolves to another site DC, most probably u need to resolve this issue 1st
Check that machine subnet to site mapping is correct

Also run below test on Machine to check its domain secure channel is correct

With netdom utility
You can reset the secure channel from the command prompt with the Netdom command as follows :
netdom reset machinename /domain:domainname
replace machinename with your computer name and domainname with your domain name
You can run this command on machinename itself, or from any other computer or domain controller as long as you are logged in with an account that has admin priviledges to the machinename computer.

The following command tests the secure channel for a computer with nltest utility
nltest /server:<ComputerName> /sc_query:<DomainName>
The following command resets the secure channel for a computer:
nltest /server:<ComputerName> /sc_reset:<DomainName>

To reset the SC between a computer and a DC with Powershell
Open PowerShell on the computer and run
Test-ComputerSecureChannel -repair

*The cmdlet requires PowerShell 2.0, which is pre-installed on Win7/2008R2.

Reboot machine once post resetting secure channel by any method above and check if it works

If still you are facing issues, I don't see any good option other than formatting machine and rebuilding OS since issue exists with single machine.
In that case you should not alter any server side settings

Mahesh
0
 

Accepted Solution

by:
haradaindustryofamerica earned 0 total points
ID: 39912444
Mahesh,

Thank you for your assistance but everything you listed above was fine.

we actually resolved it ourselves, we simply created a new folder with a different name, setup all the shares for that folder, tested the access and it worked fine for all users including the user we were having difficulties with.

Then we deleted the other folder giving us issues with the one user and renamed the good working folder to the name of the folder deleted. Everything is working fine. Still odd though.

Thanks again.
0
 

Author Closing Comment

by:haradaindustryofamerica
ID: 39922893
We discovered the solution on our own, see previous posted comment.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question