[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Folder permissions - Traversing folders to only access subfolders, multiple users

Posted on 2015-02-19
6
Medium Priority
?
2,578 Views
Last Modified: 2015-02-20
I need to setup folder permissions to an existing directory structure in a domain.

I have 4 groups of users that need access to certain subfolders on a shared drive, but should not have access to any files in any folders above those subfolders

ie: \\Server\Shares\ENG\ENG-Draw\ENG-Part

all users have a drive mapping s: to \\Server \Shares

How can I set up permissions to allow group1 access to s:\ENG\ENG-Draw\ENG-Part dir only?

I've read about the Traverse directory permission, but have never implemented it.

Any direction here is appreciated.
0
Comment
Question by:JNMarks
  • 2
  • 2
  • 2
6 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40619184
You need to remove the Inheritable permissions on the folder

Do the following...
- nav to that folder (s:\ENG\ENG-Draw\ENG-Part)
- Right click, Properties
- Click Security Tab
- Click Advance button
- Click Change permissions button
- remove the check mark for "include inheritable permissions from this objects parent"
- Click the Add button ( this will allow you to add to this current list of users that have already been populated)
- Click Add button and add Group1
- Set the permissions for Group1

Will.
0
 
LVL 39

Accepted Solution

by:
Mahesh earned 900 total points
ID: 40619478
In your case 1st thing to do:

Ensure that share root has "authenticated users" have full control share permissions
disable permissions inheritance on root share folder advanced NTFS permissions with convert explicit option
Then grant "authenticated users" List folder contents permissions on root share
Remove any explicit groups if defined here on ACL

Now go to "Eng-Part" folder and disable inheritance and change authenticated users permissions scope (Applied to) to this Folder Only
Then add required group required access here

This process to followed for all other groups

This will ensure that group members will able to access only folders for which they have access
Also you may enable access based enumeration on share folder so that folders get hide from explorer for which user do not have permissions
http://heineborn.com/tech/enable-access-based-enumeration-in-windows-server-2012/
0
 

Author Comment

by:JNMarks
ID: 40619813
Thanks for the responses.

There are about 10 other dirs under Shares, (Sales, Prod, Quality, etc.) and then several under each one of them.

If I give full share permissions, and disable inheritance, I will have to assign/remove NTFS permissions manually to every subfolder, and then manually to every subfolder's subfolder.

ie Managers need full access to all folders, and the same groups may need access to other specific directories within the structure.

Assigning permissions manually will be a headache especially if a new folder is created.

Is there any other way?

Are you familiar with implementing the Traversal permission?

Thanks again,
0
Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 600 total points
ID: 40619850
You leave Share permissions for Everyone to Full. You then only modify Security Permissions for Security only. depending on how granular you want to have this you will need to do this manually. The other option would be to create new Shares and apply permissions accordingly for each  security groups.

Will.
0
 
LVL 39

Expert Comment

by:Mahesh
ID: 40620599
Its not required, by disabling inheritance, you don't have to set permissions manually on sub folders
Sub folders still will get inherited permissions from root share

If manager group require full permissions, you can grant them Modify \ full NTFS permissions on folder root once, it will get propagated to all sub folders

I have asked you to disable inheritance on share root because it is best practice and only way to stop flowing drive level permissions on root share
Whatever explicit permissions you will apply on root share will not affected by disabling inheritance.

Check below article for best practices to setup share folders
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_17526-NTFS-File-System-Folder-ownership-problems-and-resolution.html
0
 

Author Closing Comment

by:JNMarks
ID: 40621164
Thanks both of you for your quick responses.

I was able to get the permissions functioning the way I needed by blocking inheritance, converting and editing NTFS permissions on the folders and sub folders accordingly.

Thanks again for pointing me in the right direction.
0

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question