Active Directory Folder security change

Setup a new folder with security rights for only specific individuals.

For one of the allowed users he cannot access the folder on his current workstation, but if the he logs into another workstation or into Terminal Services server session, he can access the folder and has all the rights he should have. It is just on his personal workstation that he cannot access the folder.

Rebooted, logged him back in and still no access.
haradaindustryofamericaManager, Information SystemsAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Brian PiercePhotographerCommented:
Sounds like an issue with the SHARE permissions - check these as well as NTFS
0
haradaindustryofamericaManager, Information SystemsAuthor Commented:
I see no issues with either. He can log into any other machine on our network and access the folder fine, only his machine has problem accessing.
0
Brian PiercePhotographerCommented:
Check that the computer in question is authenticating to the network OK. It may have an issue and is logging on the user using cached credentials.
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

MaheshArchitectCommented:
just remove affected machine from domain once and re-join to domain and try

On affected computer please open Advanced Tcp/IP settings and check DNS Tab.
In DNS tab, check below settings.
ensure that "Append Primary and connection specific dns suffixes" radio button is selected
Ensure that "Append parent suffixes of primary dns suffix" checkbox is selected
Ensure that "register this connection addresses in Dns" checkbox is selected
If there is any deviation in the above settings, its probably you will face name resolution and network access issues

Mahesh
0
haradaindustryofamericaManager, Information SystemsAuthor Commented:
Mahesh -

Tried removing and adding back to domain, still has issue.

All the settings you referenced above were set already.

We had another user in his department with the same access rights as him log into his machine, they can access the folder fine. This is very weird.
0
haradaindustryofamericaManager, Information SystemsAuthor Commented:
Does anyone have any other ideas?

Thanks in advance.
0
MaheshArchitectCommented:
Run rsop.msc on the affected machine and check if any specific policy denying that machine from accessing network shares ?
Also check if you can access any other share folders on other servers from this machine ?

Also check if you can access netlogon and sysvol share folders on domain controllers

Go to run and enter %logonserver%
This should resolve to NetBIOS name of its local authenticating DC
if here you get error or it resolves to another site DC, most probably u need to resolve this issue 1st
Check that machine subnet to site mapping is correct

Also run below test on Machine to check its domain secure channel is correct

With netdom utility
You can reset the secure channel from the command prompt with the Netdom command as follows :
netdom reset machinename /domain:domainname
replace machinename with your computer name and domainname with your domain name
You can run this command on machinename itself, or from any other computer or domain controller as long as you are logged in with an account that has admin priviledges to the machinename computer.

The following command tests the secure channel for a computer with nltest utility
nltest /server:<ComputerName> /sc_query:<DomainName>
The following command resets the secure channel for a computer:
nltest /server:<ComputerName> /sc_reset:<DomainName>

To reset the SC between a computer and a DC with Powershell
Open PowerShell on the computer and run
Test-ComputerSecureChannel -repair

*The cmdlet requires PowerShell 2.0, which is pre-installed on Win7/2008R2.

Reboot machine once post resetting secure channel by any method above and check if it works

If still you are facing issues, I don't see any good option other than formatting machine and rebuilding OS since issue exists with single machine.
In that case you should not alter any server side settings

Mahesh
0
haradaindustryofamericaManager, Information SystemsAuthor Commented:
Mahesh,

Thank you for your assistance but everything you listed above was fine.

we actually resolved it ourselves, we simply created a new folder with a different name, setup all the shares for that folder, tested the access and it worked fine for all users including the user we were having difficulties with.

Then we deleted the other folder giving us issues with the one user and renamed the good working folder to the name of the folder deleted. Everything is working fine. Still odd though.

Thanks again.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
haradaindustryofamericaManager, Information SystemsAuthor Commented:
We discovered the solution on our own, see previous posted comment.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.