Solved

I need to find out what effective permissions have been applied to a share on my sbs 2008 server

Posted on 2016-11-08
7
72 Views
Last Modified: 2016-11-12
In AD .

I have a company\partner  share .  
I have assigned 3 users to a group called partners
I have given the group full rights to partner share
but when I try to access the share as one of the users
I am getting a message saying I do not have permission to access .
I am not sure if another admin has setup permissions separately which is more restrictive .
This was working a few days ago .
How do I check this ?
When I checked the share from the server
under security the users are given rights to the share individually AND the partner group there of which they are members
why isnt it giving the correct permissions ?
Can AD be malfunctioning ? How can I check ?
0
Comment
Question by:Andre P
7 Comments
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 41879899
Access to a share is controlled by two things. Share permissions and NTFS permissions. The most restrictive permissions apply. I follow the old proactive of having everyone full permissions on the share, and then set the effective permissions via NTFS.

Here's how to set/check NTFS permissions.

http://www.ntfs.com/ntfs-permissions-setting.htm
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 41879916
Have you added partner group "Modify" share permissions on sharing tab, else this is what expected
0
 

Author Comment

by:Andre P
ID: 41879954
It has full permissions .
so does the permissions on the directory. .what could over write that and give me access denied message when logging in as a member of partner share ?
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 36

Expert Comment

by:Mahesh
ID: 41879960
how you are trying to access share with member of partner group?

Are you logging on to workstation with account having partner group membership?

What is happening in that case?
Because you have added partner group on share tab and individual user on NTFS tab

Also try adding partner group on NTFS tab with required permissions

also logon to server with account having local admin member and check partner group and it members for effective access from shared folder NTFS permissions\advanced properties\effective access tab

If wanted, to you may take folder ownership for admin ID and then remove and add partner group again on share and NTFS tabs with required permissions
You can use MS tool called Subinacl to take folder ownership without destroying existing folder permissions
Check below article for Subinacl commands
https://www.experts-exchange.com/articles/17526/Windows-File-Server-Folder-ownership-problems-and-resolution.html
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 250 total points
ID: 41879999
Three things:
1 NTFS permissions can be read out (and published here) using
icacls c:\yourfolder
2 share permissions like this:
net share yoursharenamehere
->Publish the output of both here.
3 "Share permissions and NTFS permissions - The most restrictive permissions apply" is not entirely correct. It is mostly correct, but it has exceptions, please see https://www.experts-exchange.com/questions/22108365/NTFS-and-share-permissions-I-found-a-difference-where-there-should-not-be-any.html
0
 
LVL 27

Accepted Solution

by:
Thomas Zucker-Scharff earned 250 total points
ID: 41882652
Netwrix has a free tool to check permissions (https://www.netwrix.com/netwrix_effective_permissions_reporting_tool.html).
0
 
LVL 54

Expert Comment

by:McKnife
ID: 41884522
Andre, please report what you achieved with the netwrix tool and if it can really provide the same info as the commands I listed.
Also, I wonder if it notices the "exception to the rule" which I also linked. I guess I'll have to try it.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VPN problems 4 31
Extend AD schema for SCCM 2012 3 28
O365 Getting Spoofed from Another Country 4 28
Website Question - New Site 3 13
In this increasingly digital world, security hacks are no longer just a threat, but a reality. As we've witnessed with Target's big identity hack 2013, Heartbleed in 2015, and now Cloudbleed, companies and their leaders need to prepare for the unthi…
There's a lot of hype surrounding blockchain technology. Here's how it works and some of the novel ways it' s now being used - including for data protection.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question