Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Server 2012

Posted on 2014-02-28
20
Medium Priority
?
545 Views
Last Modified: 2014-03-03
I have a 2012 server that I am working with.  I am very new to 2012.

I have a user folder that that I want to share.  It used to be in 2008 I could share the top level with authenticated users check all three boxes and then on the security tab.  I could control who could get access to what folder.  Here is what the folder setup looks like.

User - top level folder want to be able to read the subfolders
     abcsuer sub folder only want that user to get into the folder.
     xyzuser
     lmnuser

But it seems like that in 2012 it is either an all or nothing case.  I can not just give authenticated users in the share permission and then in the security tab just give the user who needs access access to their folder.

I would really appreciate some help.

Thanks,

Rick
0
Comment
Question by:RickArnold
20 Comments
 
LVL 7

Expert Comment

by:Sivaraj E
ID: 39896467
@ Rick - This need to be done on Server Manager, To understand in brief please have allok at the link below

www.techrepublic.com/blog/data-center/how-to-share-a-folder-in-windows-server-2012/

Regards, Shiva
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39897037
2012 works the same as previous versions with regards to permissions in your scenario. You can open up the share, and then limit the NTFS permissions on the subfolders as you see fit. Where specifically are you getting stuck in the process?
0
 
LVL 11

Expert Comment

by:gmbaxter
ID: 39897289
Use server manager to set the top level share permissions, then use windows explorer to set the security on the subfolders
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:RickArnold
ID: 39897327
Cliff,

the top level folder is called users then there are multiple folders in the user folder that contain their data.  

I want everybody in the Domain to be able to click the top level folder and see the folders,
but when it comes to the individual folders only the owner is able to get into the folder.

Thanks,

Rick
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39897333
I already understood that. But you said you did this in 2008, and I'm saying the way shares and NTFS permissions work in 2012 hasn't changed. So my question for you is where are you getting stuck?
0
 

Author Comment

by:RickArnold
ID: 39897385
Cliff,

I am getting stuck at the top level.  In my Lab I have set this up. This example should work the should when i get to the production network.

In the Lab

Driver folder  Share Tab

Everyone
Full control x
change        x
Read            x

Then I get into the driver folder I right click a folder inside go to the properties

Click the security tab
Edit button
and then I give my test user full control of that folder.
Everyone is not in the  Security Tab

However when those permissions are applied in that way, the test user cannot open the drivers folder over the network

Thanks,

Rick
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39897389
Error?
0
 

Author Comment

by:RickArnold
ID: 39897398
Network Error

Windows cannot access \\server01\Drivers

You do not have permissions to access \\server01\drivers ....
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39897411
Please post screen shots of the network permissions and NTFS permissions for both the shared folder and subfolder, as well as the username you are attempting your test with.
0
 

Author Comment

by:RickArnold
ID: 39897491
OK,

I changed it a little to be more like the Production network.  

The user folder is visible from \\server01 the user share is visible.  When I click on it "Windows Cannot Access  \\Server01\ users

What I would like is to have the users click on the user folder get in, but when they click on a folder that is not theirs they are not able to open that folder.

Thanks very much for the help,

Rick
Users---Top-Level-Sharing.PNG
Users---Top-Level-Security.png
User-Folder---Sharing-Tab.PNG
User---Security-Tab-Rick-Ben-is-.PNG
User-Folder-From-Client-Rickb.PNG
0
 
LVL 59

Accepted Solution

by:
Cliff Galiher earned 2000 total points
ID: 39897513
Well, the problem is that you didn't give NTFS permissions to the top level folder (security tab) so you are getting access denied. A user must both have share *and NTFS permissions. And just so we are clear, this isn't new in 2012. Your 2008 setup had to be this way too.

Add a group (I don't like "everyone" when a security group is better) and give them read permissions. I think you'll see your problem disappear.
0
 
LVL 59

Assisted Solution

by:Cliff Galiher
Cliff Galiher earned 2000 total points
ID: 39897618
Inheritance. On the security tab if the top level folder,  go into advanced, and change the permissions for domain users from folders, subfolder, and file to folder only so it won't grant read permissions to the subfolders.
0
 

Author Comment

by:RickArnold
ID: 39897667
Cliff,

That did it. I forgot about that.  That worked I should be able to take this back to production!

Rick
0
 

Author Comment

by:RickArnold
ID: 39898141
I've requested that this question be closed as follows:

Accepted answer: 0 points for RickArnold's comment #a39897667

for the following reason:

Awesome effort !
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39898142
You accepted your own comment as the answer after I walked you through all the permissions?!?
0
 

Author Comment

by:RickArnold
ID: 39901341
Cliff,

I hit the wrong button very sorry about that.  I meant to say Awesome effort Cliff.  I saw the objection this morning my mistake and my apologies.  

I do  have another question regarding the  permissions.  It works like I want but the reported can not save into the folder.

thanks,

Rick
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39901355
Well, based on the screenshots you posted, the share permissions (not the NTFS permissions) only grant read access. So that is to be expected. Add write permissions to the share and things should work as expected.
0
 

Author Comment

by:RickArnold
ID: 39901473
Cliff,

that worked great.  Thanks again have a great week!

Rick
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The following article is comprised of the pearls we have garnered deploying virtualization solutions since Virtual Server 2005 and subsequent 2008 RTM+ Hyper-V in standalone and clustered environments.
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
Suggested Courses

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question