Solved

Notification of security restrictions on NTFS folders.

Posted on 2015-01-12
4
183 Views
Last Modified: 2015-01-12
I have some folders on a company share that supervisors have requested certain people have access and only one person can approve changes.

We have a handful of people in IT that can give users rights.  Many times rights are based on similar job roles.

I thought about making new groups that would indicate higher security is enforced.  (ex: Approved_Access_Support_Dept)

Anyone know of any way to alert IT staff that a folder has more restrictions than others?  We do try to check with a folder owner however much of the decision is based on department or role.  We are also not interested in adding any additional software on the server.   Readme files only work if you go into each folder/subfolder to see if any are there.  
They do not want to change the name of the folders.   Thanks
0
Comment
Question by:PostQ
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 9

Expert Comment

by:Trenton Knew
ID: 40545115
I'm not sure I have a clear understanding of your question.  You want to know users or groups have security permissions on folders, or are you looking for a script to step through and list permissions on folders in a share?  I'm assuming you aren't talking about an automated process that alerts an admin when permissions are changed.
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 500 total points
ID: 40545117
If you use exchange on site too then this is what we do....

Create a New AD Universal security group.  Example  DRIVE_SuportDesk
Use exchange to set this as a Mail enabled security group.
Now modify the share itself so that this group is the principle security permission on it instead of users
In the EMC edit the new Distribution groups properties and set the Manager as the person who authorises access to the share.

This user "Manager" can now use outlook to add/remove members of the distribution group and therefore give/take away rights to the share.


We also create a  DRIVE_SuportDesk_RO group for Read Only members access to the folder.

If you need any further explanations feel free and ask.
0
 
LVL 2

Author Closing Comment

by:PostQ
ID: 40545217
I think this will do what we want as well as have the share self-managed from the manager approving the users.

Thanks
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40545223
You're welcome.
0

Featured Post

WordPress Tutorial 1: Installation & Setup

WordPress is a very popular option for running your web site and can be used to get your content online quickly for the world to see. This guide will walk you through installing the WordPress server software and the initial setup process.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question