Solved

NTFS Permissions - File/Folder Owner

Posted on 2016-09-29
2
37 Views
Last Modified: 2016-10-03
Hi,

Hoping somebody can help answer me a query I have about NTFS permissions and folder owners.

We have some network shares which have a pretty standard setup. As an example on one of them, share permissions have change access for everyone and NTFS permissions are locked down to just three global groups - Generic-RO, Generic-RW and Domain Admins.

The "problem" (if it actually is one) is that if a standard user creates a folder or file, when checking the owner of that, it is listed as the user being the owner. When somebody who doesn't have Read/Write access tries to delete a file, they get the message that they need permissions from the user who created the object eg Domain\John.Smith. I was under the impression that it should be administrators that are always the folder/file owners. Looking at a lot of other folders and files on other shares we have, there seems to be a mix of the owners being either server\administrators or domain\user (the person that created the file). Some folders which I know were definitely not created by any administrator on the domain has server\administrators as the owner and others have the user as the owner. I am struggling to find an explanation for this.

Is this correct behaviour?

I assumed that the owner would always be the administrator or administrators group. As an admin, I can change ownership of the files and folders no problem but I'm not sure if the original owner issue is expected behaviour.

Please correct me if I have misunderstood how this works. If there is anybody able to offer any advice, I would very much appreciate it.

Thanks in advance.
0
Comment
Question by:MFAFC
2 Comments
 
LVL 15

Accepted Solution

by:
Ivan earned 500 total points
ID: 41821238
Hi,

owner of file/ folder is always going to be person, or rather user account, who has created it.
So, situation that you have is normal. You have mix, since many other users have created files nad folders.

As for changing ownership, you are correct that you can change it, but i don't think that you need to do that :)

Behavior of access is also normal, since usually only person who has created file/folder will have access + administrators. Other users cannot delete files, since they need additional access rights.

Regards,
Ivan.
0
 

Author Comment

by:MFAFC
ID: 41821260
Thanks for taking the time to respond, Ivan.

I was confused because some folders which I know users have created, have the owner listed as server\administrators. If my problem is default behaviour, I would expect to ALWAYS see the owner as the user who created the object, but that does not appear to be happening.

The reason I was concerned is because when looking at the effective permissions for an object where the user is the owner, it has "change permissions" as being granted. I actually tested this with a certain user and if they try to change the NTFS permissions, they do get access denied.

Do you know why it says they have change permissions when they actually don't? Is that coming from the share permissions or something?
NTFS-Owner1.png
0

Featured Post

Want to promote your upcoming event?

Are you going to an event? Are you going to be exhibiting at a tradeshow? Talking at a conference? Using a promotional banner in your email signature ensures that your organization’s most important contacts stay in the know and can potentially spread the word about the event.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Increase size of DHCP scope? 16 61
Windows 2008 R2 _MSDSC Delegation 8 38
Encryption of server 7 68
How to transfer FSMO roles 2 50
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now