Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Notification of security restrictions on NTFS folders.

Posted on 2015-01-12
4
Medium Priority
?
197 Views
Last Modified: 2015-01-12
I have some folders on a company share that supervisors have requested certain people have access and only one person can approve changes.

We have a handful of people in IT that can give users rights.  Many times rights are based on similar job roles.

I thought about making new groups that would indicate higher security is enforced.  (ex: Approved_Access_Support_Dept)

Anyone know of any way to alert IT staff that a folder has more restrictions than others?  We do try to check with a folder owner however much of the decision is based on department or role.  We are also not interested in adding any additional software on the server.   Readme files only work if you go into each folder/subfolder to see if any are there.  
They do not want to change the name of the folders.   Thanks
0
Comment
Question by:PostQ
  • 2
4 Comments
 
LVL 9

Expert Comment

by:Trenton Knew
ID: 40545115
I'm not sure I have a clear understanding of your question.  You want to know users or groups have security permissions on folders, or are you looking for a script to step through and list permissions on folders in a share?  I'm assuming you aren't talking about an automated process that alerts an admin when permissions are changed.
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 2000 total points
ID: 40545117
If you use exchange on site too then this is what we do....

Create a New AD Universal security group.  Example  DRIVE_SuportDesk
Use exchange to set this as a Mail enabled security group.
Now modify the share itself so that this group is the principle security permission on it instead of users
In the EMC edit the new Distribution groups properties and set the Manager as the person who authorises access to the share.

This user "Manager" can now use outlook to add/remove members of the distribution group and therefore give/take away rights to the share.


We also create a  DRIVE_SuportDesk_RO group for Read Only members access to the folder.

If you need any further explanations feel free and ask.
0
 
LVL 2

Author Closing Comment

by:PostQ
ID: 40545217
I think this will do what we want as well as have the share self-managed from the manager approving the users.

Thanks
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40545223
You're welcome.
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this blog we highlight approaches to managed security as a service.  We also look into ConnectWise’s value in aiding MSPs’ security management and indicate why critical alerting is a necessary integration.
How does someone stay on the right and legal side of the hacking world?
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Despite its rising prevalence in the business world, "the cloud" is still misunderstood. Some companies still believe common misconceptions about lack of security in cloud solutions and many misuses of cloud storage options still occur every day. …

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question