Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How to set File System permissions in Local Policy

Posted on 2014-03-24
3
Medium Priority
?
455 Views
Last Modified: 2014-04-10
On the domain level you can set folder permissions in Group Policy here - Computer Configuration\Windows Settings\Security Settings\File System. However, I need to be able to do this from Local Policy as the machines I am working with cannot receive Computer Group policies since they do not have connectivity until logon. Is there a way to accomplish this in Local Policy or with another method?
0
Comment
Question by:MCSF
  • 2
3 Comments
 
LVL 22

Accepted Solution

by:
Joseph Moody earned 2000 total points
ID: 39950709
0
 

Author Comment

by:MCSF
ID: 39991637
I did a lot of testing with different options and what finally worked for me was a combination of two built-in Windows command line tools that were available for Windows 7. I used takeown to set ownership on the files/folders and then used icacls to set the permissions. I first did some testing with them from the command line and then once I had them perfected I incorporated the commands into a batch file. I plan to put that batch file into the local policy as a Startup Script.

Here is an example of the commands I used. The first command takes ownership for the local Administrators group. The second gives full control to the local Users group for the folder and all sub-directories and files.

takeown /F c:\test /R /A /D Y
icacls c:\test\ /grant Users:(OI)(CI)(F)
0
 

Author Closing Comment

by:MCSF
ID: 39991639
This comment got me on the right track.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question