Solved

Windows Search results display documents in folders user cannot open

Posted on 2014-10-27
4
130 Views
Last Modified: 2014-12-11
A client's network is a mix of XP SP3 and Windows 7 machines in a domain with three W2K3 servers, one with the PDC emumulator and global catalog, the other a domain controller with shared folders and user profiles. A 3rd W2K3 runs SQL Server.

Users My Documents defaults to a share which is also available as their S: drive.

Several of the folders in the shared drive are limited to different user groups, for example only members of the executive group have access to financials.

While assisting a user who was not in the executive group via a remote session (so the system was using their credentials, not my administrative creds), I ran a search using Windows Search and noticed documents in the financials subfolder coming up and previewing data in the documents.

I opened Windows Explorer and attempted to open the financial folders, and as expected was denied access.

I then clicked on the link to the doc in Windows Search, and the document "downloaded" and opened.

Naturally I closed all this and got back to the original issue, resolved it, logged off and called the user to let them know everything was ready when they got back to the office.

I then repeated this on a couple of different systems using a test account. Same issue.

I'm thinking this must be solvable with a GPO profile setting but haven't been able to figure out what it would be.

Any Windows Search / Security masters out there with a suggestion?

We are working toward moving to 2K8/2K12 and retiring the last of the XPs. I can deploy a production 2K8 or 2K12 server immediately if need be.

Thanks!
0
Comment
Question by:F. X. Flinn
  • 2
4 Comments
 
LVL 16

Expert Comment

by:choward16980
ID: 40407042
Do you think you mapped a network drive (S:) as an admin?
0
 
LVL 54

Expert Comment

by:McKnife
ID: 40407353
Hi.

"I then clicked on the link to the doc in Windows Search, and the document "downloaded" and opened"
Please run procmon to see where that file is originating. The problem will be found instantly.
0
 
LVL 1

Accepted Solution

by:
F. X. Flinn earned 0 total points
ID: 40484841
The problem was rooted in the failure of one of the AD servers to replicate, leading to the failure of a group policy to be properly delivered to the client.
0
 
LVL 1

Author Closing Comment

by:F. X. Flinn
ID: 40493428
Once the replication issue was discovered while trying to understand why the user had unexpected access, the solution to the symptom was to fix the underlying issue or root cause of the problem.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
Read about achieving the basic levels of HRIS security in the workplace.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question