• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1357
  • Last Modified:

Allow access to just one sub folder using NTFS permissions accessing via RWW

Hi all,

I'm having a really hard time trying to get the right way to share a folder for a user on a 2011 SBS server.

I will try to simplify the setup and question as best I can.

The main document share on the server all hangs off a folder called D:\Public.  Under that we have Folder A, Folder B, Folder C etc.   Under each of those folders are many subfolders and under those many many more sub folders.

All users were set up to have full control of D:\Public and all sub folders at both share and file level.

A new consultant has just started and only accesses server documents using Remote Web Working.  The new consultant needs to be denied access to absolutely everything on the share except one sub folder all the way down the tree (Let's say D:\Public\Folder B\Clients\Smith\Jones\Projects\4)

I think I am massively over thinking and complicating this but the only way I can think of making sure he can't see anything other than the one folder is to grant access to D:\Public then go in and add the user to all subfolders and select deny apart from the one sub folder he needs.  Unfortunately due to the sheer number of folders this takes ages.  

Can someone please tell me if I can just grant access to one sub folder which will allow them access via the shared folder option in RWW but will not even show the existence of any other folder above it?

Thanks

Adam
0
amlydiate
Asked:
amlydiate
  • 2
  • 2
1 Solution
 
KCTSCommented:
Create a new share just for that sub-folder and give him access to that (only).
0
 
amlydiateAuthor Commented:
Trouble is I've made a rod for my own back by granting "Everyone" access at the top level, therefore even if I just share the sub folder to the one person they are still going to get access to everything else unless I deny permissions to all other folders...
0
 
KCTSCommented:
Deny should only be used in exceptional circumstances.
Its easy to opt for the 'quick fix' and grant permissions for everyone, more often than not this complicates matters further down the line.
I would re-visit the way you have set out the access with a view to removing permissions for 'everyone'
0
 
amlydiateAuthor Commented:
Thanks for your help
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now