Solved

NTFS/Security permissions not applying equally

Posted on 2016-08-11
4
51 Views
Last Modified: 2016-08-11
The root problem I'm trying to solve is that I have an excel file which needs to be updated by many users, keeps getting deleted or moved.  I'm trying to lock it down so users can open and write to it, but can't accidentally be deleted or moved.

File structure is a directory which contains an Excel file, and some additional subdirectories.  Files are on a Server 2012R2 file server

I've created two security groups, one with full access (admins) to everything.  The other security group (users) has Read & Execute, Read, and Write permissions.  The permissions for admins group is applied to the top directory and allowed to inherit to all directories, subdirs, and files.  Users group is also applied at top directory, and access is set to only "This folder and files" - as they should not access subfolders or any other files.  No issues at all with admins group.

I created a file test1.txt and set users group permissions as described above for that file only (for testing); it works as intended (i.e. users can open and edit file, can save file - can't move or delete file).  
So I created test2.txt and set users group permissions as describe above at the directory and allowed to inherit to test files it works as intended.  
So here's the problem: I created testexcel.xlsx with users group permissions (I tried at the file and inherited), but users can't save file.

Why are permissions not working the same with my Excel files as with my test.txt files?
0
Comment
Question by:Geisrud
  • 2
  • 2
4 Comments
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 41752929
What you're planning is not possible with Excel and NTFS, sorry.
Excel saves a file by first writing to a temporary file, and once that's successfully finished, the original file will be deleted and the new/temporary file renamed to the original name.
In other words: with every save, you get a new file, which will obviously inherit the permissions from the folder.
This means as well that the user requires delete permissions for the files being processed.
0
 
LVL 14

Author Comment

by:Geisrud
ID: 41752932
Makes sense, I was aware of the temp file, but not the rest of that saving process.

Could you provide any further insight on accomplishing my goal of protecting that file?

Thanks!

Side note, that may help explain why this directory is populating with odd .tmp files that aren't going away
0
 
LVL 83

Expert Comment

by:oBdA
ID: 41752975
There's nothing you can do with NTFS to protect that file, because it is constantly getting deleted, and this is required to be able to work with it.
You can use shadow copies/previous versions or maybe a job that copies the file every x minutes to a safe location.
0
 
LVL 14

Author Comment

by:Geisrud
ID: 41752982
Thanks - we already have shadow copy in place, which we've been using to recover the deleted file.  The only problem with that is the file is updated so frequently, that some updates can be lost since the most recent backup.

I guess those are the breaks.  Thanks for all the help and insight!
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the biggest threats in the cyber realm pertains to advanced persistent threats (APTs). This paper is a compare and contrast of Russian and Chinese APT's.
How do we balance the user experience (UX) with reasonable security measures? It can be done, if you keep these fundamentals in mind.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question