Making a file accessible to a user with limited permissions for an SBS 2011 standard server

Situation is that there's 3 groups of users - A, B, C.  

users in group A can access folder 1 & 2.  
users in group B can access folder 2
users in group C cannot access folder 1 and 2

There's a file in folder 1 that all A users have a shortcut to \\server\folder1\doc on their desktops because they use it so much.

Now they want group B to be able to access that file.

How would you do this to make sure the desktop shortcuts all still work, group B can access the file and group C cannot.

some ways I can think of it:

give group B permission to just that file?  But how much of folder 1 can they see then?  File names?...
Move file to folder2 and change all the shortcuts?
Something else?
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

JohnBusiness Consultant (Owner)Commented:
Rather than muck with individual file permissions (which can have unintended consequences), I suggest you put the file in a common folder that is permitted to people who need the file.

That is how I approach folder permission issues.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
BeGentleWithMe-INeedHelpAuthor Commented:
and then change / make a new shortcut on each user's desktop?  If the shortcut goes to \\server\folder1\doc, you can't really replace that target location with another shortcut to \\server\folder2\doc?
JohnBusiness Consultant (Owner)Commented:
I make the folder structure so that it fits the permissions requirements and then adjust shortcuts to fit.
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Joseph OLoughlinIT Support SpecialistCommented:
The file is one file as regards permissions, so grant group b permissions to the specific file via it's security properties.
Create a symlink to the file in folder 2
BeGentleWithMe-INeedHelpAuthor Commented:
john - yeah, that's what I would do (put the file somewhere then create shortcut), but the situation changed : )

And Joe - you are saying leave the file in folder 1, allow group B to get to it via a symlink?  hadn't heard of a symlink before and not really following the page you point to. is that any different than just making a shortcut on their desktop to \\server\folder1\doc?

I will likely try it to see for myself, but now, when they type \\server in win explorer, they see all the shares, but when group b clicks on any other than folder2, they get a message about not permitted.  what happens when they have permission to 1 file in a folder they don't have permissions for?!
RantCanSr. Systems AdministratorCommented:
Give group B list and read permission to the folder that hosts the file they need in folder 1, and then give them write access to the file they need.
Joseph OLoughlinIT Support SpecialistCommented:
It's like a shortcut, but at a lower ntfs level.  Delete it in one place, it's gone from both.  MS use this trick with My Documents / Documents folder.  I suggested it so you would not need to change folder permissions.
BeGentleWithMe-INeedHelpAuthor Commented:
RantCan:  I think I did this:

Give group B list and read permission to the folder that hosts the file they need in folder 1, and then give them write access to the file they need.

in permissions for the folder1, it says

allow  group b  list folder / read data not inherited   this folder only.

Sound right?

when I type \\server\folder 1 from the group 2 user's machine, I get 'you don't have permission'.

is there the equivalent of gpupdate /force that you have to do when you change permissions for a file?  I rebooted.

Now if I type \\server\folder1, I see the file.  I click on it, it opens.  I make a change, hit save and it says it can't find the file \\server\folder1

Any thoughts?

Something else, \\server\folder1 is a share to the same folder as \\server\f1

browsing in internet explorer to \\server\folder1, I only see that 1 file.

But browsing to \\server\f1, I see all the files?  Both shares have permissions of full for everyone.  ANy thoughts on why 1 share shows all files (can't open them though) and 1 share shows only that 1 file?
RantCanSr. Systems AdministratorCommented:
Try adding "traverse" to the NTFS permission so they can navigate to the file they have access to.

Also, what do the *share* permissions look like? Standard is to set those to "Authenticated Users" Full Control.
Joseph OLoughlinIT Support SpecialistCommented:
stop confusing folder permissions and share permissions.  Both need to be set correctly, as they were when I recommended you instead change the file permissions and create a symbolic link.
changes to share permissions, file system and registry permissions are instantaneous.  your app will need to be reopened.
the user used by internet information server, if this is providing the page to internet explorer is different to the logged in user
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 7

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.