Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

NTFS Permissions - File/Folder Owner

Posted on 2016-09-29
2
Medium Priority
?
91 Views
Last Modified: 2016-10-03
Hi,

Hoping somebody can help answer me a query I have about NTFS permissions and folder owners.

We have some network shares which have a pretty standard setup. As an example on one of them, share permissions have change access for everyone and NTFS permissions are locked down to just three global groups - Generic-RO, Generic-RW and Domain Admins.

The "problem" (if it actually is one) is that if a standard user creates a folder or file, when checking the owner of that, it is listed as the user being the owner. When somebody who doesn't have Read/Write access tries to delete a file, they get the message that they need permissions from the user who created the object eg Domain\John.Smith. I was under the impression that it should be administrators that are always the folder/file owners. Looking at a lot of other folders and files on other shares we have, there seems to be a mix of the owners being either server\administrators or domain\user (the person that created the file). Some folders which I know were definitely not created by any administrator on the domain has server\administrators as the owner and others have the user as the owner. I am struggling to find an explanation for this.

Is this correct behaviour?

I assumed that the owner would always be the administrator or administrators group. As an admin, I can change ownership of the files and folders no problem but I'm not sure if the original owner issue is expected behaviour.

Please correct me if I have misunderstood how this works. If there is anybody able to offer any advice, I would very much appreciate it.

Thanks in advance.
0
Comment
Question by:MFAFC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 17

Accepted Solution

by:
Ivan earned 2000 total points
ID: 41821238
Hi,

owner of file/ folder is always going to be person, or rather user account, who has created it.
So, situation that you have is normal. You have mix, since many other users have created files nad folders.

As for changing ownership, you are correct that you can change it, but i don't think that you need to do that :)

Behavior of access is also normal, since usually only person who has created file/folder will have access + administrators. Other users cannot delete files, since they need additional access rights.

Regards,
Ivan.
0
 

Author Comment

by:MFAFC
ID: 41821260
Thanks for taking the time to respond, Ivan.

I was confused because some folders which I know users have created, have the owner listed as server\administrators. If my problem is default behaviour, I would expect to ALWAYS see the owner as the user who created the object, but that does not appear to be happening.

The reason I was concerned is because when looking at the effective permissions for an object where the user is the owner, it has "change permissions" as being granted. I actually tested this with a certain user and if they try to change the NTFS permissions, they do get access denied.

Do you know why it says they have change permissions when they actually don't? Is that coming from the share permissions or something?
NTFS-Owner1.png
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question