How to change NTFS permission to the folder based on the time of the day?

Active Directory group ‘Help Desk’ will have ‘Read & execute’ permission to the ‘Support’ folder between 7 am – 5 pm. All other time access to the ‘Support’ folder for 'Help Desk' AD group must be denied.
 
I’m guessing that I need to create two batch files which will be running on the Windows 2008 R2 file server. One is to enable NTFS permission on a folder, and second one is to disable NTFS permission. First batch file I will run as a scheduler task at 7 am (to enable permission) and second batch file will be running as a scheduler task at 5 pm (to disable permission)

I need some help with creating these permission controlling batch files. If the batch file failed to run successfully I need to know about it.

Thanks in advance.
LVL 1
OlevoAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Steve KnightIT ConsultancyCommented:
Just quick look here at the mo., that sounds potentially all sorts of issues with permissons given to folders below helpdesk being removed etc?

Also would a possible way may be to make sure the folder is only accessible via its own share and adjust the share permissions, or even remove the share at different times of day?

Can help with scripts later if no-one else has.

Steve
0
Gerwin Jansen, EE MVETopic Advisor Commented:
I'd remove/add the group that gives rights from the Helpdesk group instead of changing ntfs rights.
0
Steve KnightIT ConsultancyCommented:
That was the other way I was thinking too, if you remove the users from the groups of course it will not work because the user would still have access to that group's data until they logged off.

So thinking this through.... assuming it is part of an existing shared drive and can't be it's own share to simplify things then:

User A = member of users_Helpdesk group
Helpdesk directory has permissions at NTFS level for permissions_Helpdesk group
users_Helpdesk group is in permissions_Helpdesk group...

So does that work if you remove the group?

Also another way maybe would be to add / remove a "Deny" for the Helpdesk group to NTFS, or the share permissions.

Olevo - can you clarify if share methods is feasible?

Steve
0
Introducing the "443 Security Simplified" Podcast

This new podcast puts you inside the minds of leading white-hat hackers and security researchers. Hosts Marc Laliberte and Corey Nachreiner turn complex security concepts into easily understood and actionable insights on the latest cyber security headlines and trends.

OlevoAuthor Commented:
Help Desk group just an example here. Since I don’t know how to block users (DirectAccess) from accessing some of the company resources remotely, I thought that simple NTFS permission will do the trick for me. Basically, we don’t want our users to have remote access to few network folders after 5 pm!

I am thinking of using iCACLS.exe (or similar utility) in my batch file for changing folder permission. However, I am a bit stack with the syntax of the command.
0
Steve KnightIT ConsultancyCommented:
Switch the server off :-)
0
Steve KnightIT ConsultancyCommented:
Sorry... are these just select folders within mapped drives / UNC / DFS shares that they need access to other folders still at any time?

Steve
0
Steve KnightIT ConsultancyCommented:
I think if you did want to use icacls etc. you could do it like this to add a "deny" then remove it... have amended these from similar scripts I use for adding already so think they are right but obviously test on a sample or one with simple ntfs structure under that point!

Add Deny for HelpDeskgroup to all files and folders below X:\Helpdesk

icacls x:\Helpdesk /deny domain\HelpdeskGroup:f /c /t

Open in new window


Reset permissions to inherit from above Helpdesk

icalcs x:\Helpdesk /reset /c /t

Open in new window


Remove any deny entries under x:\Helpdesk for the group:

icacls x:\Helpdesk /remove:d domain\HelpdeskGroup /c /t

Open in new window


Steve
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
OlevoAuthor Commented:
Thanks Steve, after running command:

icacls x:\Helpdesk /deny domain\HelpdeskGroup:f /c /t

Permission applied to files but not folders (failed processing) within 'Helpdesk' folder. And, 'HelpDesk' group still have access to 'HelpDesk' folder?!

Since denying or granting permission takes time to propagate down the ACL chain, doing this two times a day for a folder with thousands of files and folders might be not so good idea to do... And, what about if the user/s belongs to multiple groups and this groups have different permission on a 'HelpDesk' folder. However I think, explicit deny will win anyway...

Maybe simply changing name of the folder or share is far better and simpler solution in my case? What do you think?
0
Steve KnightIT ConsultancyCommented:
deny will always lose over another group so a specific deny to Helpdesk.

If it can be mapped only via a specific share then all you have to do is either stop the share at specific times of day and re-add it, or add/remove the share permissions to deny.  Other non-helpdesk users could get to it from a different share.

e.g.  ShareA = All users who need it.  Put "deny" for Helpdesk users group, map 'normal' users here who need it
ShareB = Added  and removed...

net share HelpdeskShare=x:\data\helpdesk /grant:Helpdeskgroup,read
net share HelpdeskShare /delete

Would mean maybe moving the folder to a different area if currently on a general shared area so that they can only get to it that route though.

If that is an option the share permissions apart from adding like above can be done from VBScript or powershell afaik.

Steve
0
Steve KnightIT ConsultancyCommented:
Did you get anywhere with this, need any more help?
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Powershell

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.