Solved

Access shared folder in another domain

Posted on 2014-04-25
7
474 Views
Last Modified: 2014-04-25
I have a file server (Win 2008 Enterprise R2) in DOMAIN-A which holds a share named SHARE-A.
In DOMAIN-B all the users are located.
There is a Trust relasionship (two-way) between DOMAIN-A and DOMAIN-B.

I have given DOMAIN-B\USER-B Full Controll Permissions to SHARE-A (both NTFS and share permissions).

When USER-B tries to access the share (\\domain-a\share-a) he can se the folder and its contents, but though he has Full Controll permissions, he can't add new files (Destination Folder Access Denied).

What am I doing wrong here?
0
Comment
Question by:Kasper Katzmann
  • 3
  • 3
7 Comments
 

Expert Comment

by:FF-ExEx
ID: 40022494
From what you are descirbing everything looks good and it should work. I would make sure that no other permissions are present at share or folder (NTFS) level espacially no deny permission at NTFS level because this would overwrite every allow permission.
0
 

Author Comment

by:Kasper Katzmann
ID: 40022530
My thoughts exactly.
It's a completely new file server and the only permissions set after installation are those descibed above. There are no deny permissions at all.
0
 

Expert Comment

by:FF-ExEx
ID: 40022556
Ok, since this are two domains you should make sure that this is at least working for users from domain a. Setup the same permissions for a user from domain a and check if this working.

If this is also not working can you post screenshots about the configured permissions?
0
 

Author Comment

by:Kasper Katzmann
ID: 40022575
Oops... same problem with a local domain account. Why...? I ask my self...
0
 

Expert Comment

by:FF-ExEx
ID: 40022597
Difficult to help from here without seeing what exactly is set. A few screenshots with the set permissions would help.
0
 
LVL 12

Accepted Solution

by:
Sandeep earned 500 total points
ID: 40022619
If both NTFS and share permissions are defined correctly but still not working?

I would say remove those permissions and add those back. Also while adding make sure you choosing the option to replicate\propogate the change to child objects. So these permissions gets applied in same manner down the line.

See if this works.
0
 

Author Closing Comment

by:Kasper Katzmann
ID: 40023856
Of course, inheritable permissions. So simple that I missed it. Thanks for pointing it out for me.
0

Join & Write a Comment

Suggested Solutions

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now