Solved

Folder permissions - Traversing folders to only access subfolders, multiple users

Posted on 2015-02-19
6
1,155 Views
Last Modified: 2015-02-20
I need to setup folder permissions to an existing directory structure in a domain.

I have 4 groups of users that need access to certain subfolders on a shared drive, but should not have access to any files in any folders above those subfolders

ie: \\Server\Shares\ENG\ENG-Draw\ENG-Part

all users have a drive mapping s: to \\Server \Shares

How can I set up permissions to allow group1 access to s:\ENG\ENG-Draw\ENG-Part dir only?

I've read about the Traverse directory permission, but have never implemented it.

Any direction here is appreciated.
0
Comment
Question by:JNMarks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 40619184
You need to remove the Inheritable permissions on the folder

Do the following...
- nav to that folder (s:\ENG\ENG-Draw\ENG-Part)
- Right click, Properties
- Click Security Tab
- Click Advance button
- Click Change permissions button
- remove the check mark for "include inheritable permissions from this objects parent"
- Click the Add button ( this will allow you to add to this current list of users that have already been populated)
- Click Add button and add Group1
- Set the permissions for Group1

Will.
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 300 total points
ID: 40619478
In your case 1st thing to do:

Ensure that share root has "authenticated users" have full control share permissions
disable permissions inheritance on root share folder advanced NTFS permissions with convert explicit option
Then grant "authenticated users" List folder contents permissions on root share
Remove any explicit groups if defined here on ACL

Now go to "Eng-Part" folder and disable inheritance and change authenticated users permissions scope (Applied to) to this Folder Only
Then add required group required access here

This process to followed for all other groups

This will ensure that group members will able to access only folders for which they have access
Also you may enable access based enumeration on share folder so that folders get hide from explorer for which user do not have permissions
http://heineborn.com/tech/enable-access-based-enumeration-in-windows-server-2012/
0
 

Author Comment

by:JNMarks
ID: 40619813
Thanks for the responses.

There are about 10 other dirs under Shares, (Sales, Prod, Quality, etc.) and then several under each one of them.

If I give full share permissions, and disable inheritance, I will have to assign/remove NTFS permissions manually to every subfolder, and then manually to every subfolder's subfolder.

ie Managers need full access to all folders, and the same groups may need access to other specific directories within the structure.

Assigning permissions manually will be a headache especially if a new folder is created.

Is there any other way?

Are you familiar with implementing the Traversal permission?

Thanks again,
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 200 total points
ID: 40619850
You leave Share permissions for Everyone to Full. You then only modify Security Permissions for Security only. depending on how granular you want to have this you will need to do this manually. The other option would be to create new Shares and apply permissions accordingly for each  security groups.

Will.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 40620599
Its not required, by disabling inheritance, you don't have to set permissions manually on sub folders
Sub folders still will get inherited permissions from root share

If manager group require full permissions, you can grant them Modify \ full NTFS permissions on folder root once, it will get propagated to all sub folders

I have asked you to disable inheritance on share root because it is best practice and only way to stop flowing drive level permissions on root share
Whatever explicit permissions you will apply on root share will not affected by disabling inheritance.

Check below article for best practices to setup share folders
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_17526-NTFS-File-System-Folder-ownership-problems-and-resolution.html
0
 

Author Closing Comment

by:JNMarks
ID: 40621164
Thanks both of you for your quick responses.

I was able to get the permissions functioning the way I needed by blocking inheritance, converting and editing NTFS permissions on the folders and sub folders accordingly.

Thanks again for pointing me in the right direction.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question