Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Active Directory Folder security change

Posted on 2014-02-26
9
Medium Priority
?
176 Views
Last Modified: 2014-03-12
Setup a new folder with security rights for only specific individuals.

For one of the allowed users he cannot access the folder on his current workstation, but if the he logs into another workstation or into Terminal Services server session, he can access the folder and has all the rights he should have. It is just on his personal workstation that he cannot access the folder.

Rebooted, logged him back in and still no access.
0
Comment
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
  • 2
9 Comments
 
LVL 70

Expert Comment

by:KCTS
ID: 39890471
Sounds like an issue with the SHARE permissions - check these as well as NTFS
0
 

Author Comment

by:haradaindustryofamerica
ID: 39890489
I see no issues with either. He can log into any other machine on our network and access the folder fine, only his machine has problem accessing.
0
 
LVL 70

Expert Comment

by:KCTS
ID: 39890504
Check that the computer in question is authenticating to the network OK. It may have an issue and is logging on the user using cached credentials.
0
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

 
LVL 38

Expert Comment

by:Mahesh
ID: 39893069
just remove affected machine from domain once and re-join to domain and try

On affected computer please open Advanced Tcp/IP settings and check DNS Tab.
In DNS tab, check below settings.
ensure that "Append Primary and connection specific dns suffixes" radio button is selected
Ensure that "Append parent suffixes of primary dns suffix" checkbox is selected
Ensure that "register this connection addresses in Dns" checkbox is selected
If there is any deviation in the above settings, its probably you will face name resolution and network access issues

Mahesh
0
 

Author Comment

by:haradaindustryofamerica
ID: 39900751
Mahesh -

Tried removing and adding back to domain, still has issue.

All the settings you referenced above were set already.

We had another user in his department with the same access rights as him log into his machine, they can access the folder fine. This is very weird.
0
 

Author Comment

by:haradaindustryofamerica
ID: 39907680
Does anyone have any other ideas?

Thanks in advance.
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 39908541
Run rsop.msc on the affected machine and check if any specific policy denying that machine from accessing network shares ?
Also check if you can access any other share folders on other servers from this machine ?

Also check if you can access netlogon and sysvol share folders on domain controllers

Go to run and enter %logonserver%
This should resolve to NetBIOS name of its local authenticating DC
if here you get error or it resolves to another site DC, most probably u need to resolve this issue 1st
Check that machine subnet to site mapping is correct

Also run below test on Machine to check its domain secure channel is correct

With netdom utility
You can reset the secure channel from the command prompt with the Netdom command as follows :
netdom reset machinename /domain:domainname
replace machinename with your computer name and domainname with your domain name
You can run this command on machinename itself, or from any other computer or domain controller as long as you are logged in with an account that has admin priviledges to the machinename computer.

The following command tests the secure channel for a computer with nltest utility
nltest /server:<ComputerName> /sc_query:<DomainName>
The following command resets the secure channel for a computer:
nltest /server:<ComputerName> /sc_reset:<DomainName>

To reset the SC between a computer and a DC with Powershell
Open PowerShell on the computer and run
Test-ComputerSecureChannel -repair

*The cmdlet requires PowerShell 2.0, which is pre-installed on Win7/2008R2.

Reboot machine once post resetting secure channel by any method above and check if it works

If still you are facing issues, I don't see any good option other than formatting machine and rebuilding OS since issue exists with single machine.
In that case you should not alter any server side settings

Mahesh
0
 

Accepted Solution

by:
haradaindustryofamerica earned 0 total points
ID: 39912444
Mahesh,

Thank you for your assistance but everything you listed above was fine.

we actually resolved it ourselves, we simply created a new folder with a different name, setup all the shares for that folder, tested the access and it worked fine for all users including the user we were having difficulties with.

Then we deleted the other folder giving us issues with the one user and renamed the good working folder to the name of the folder deleted. Everything is working fine. Still odd though.

Thanks again.
0
 

Author Closing Comment

by:haradaindustryofamerica
ID: 39922893
We discovered the solution on our own, see previous posted comment.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

596 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question