Solved

Home folder in File server

Posted on 2016-11-16
8
54 Views
Last Modified: 2016-11-21
When I create a user in my AD, it creates a profile in my file server.

Ex.

I created a user named user1

In my file server, there is a shared folder where a profile is created.

\\fileserver\home\user1

under user1 profile it has

Documents
Desktop
Downloads
Pictures

When I am logged in as Administrator in the fileserver itself.  It always gives me an "access denied" error when I try to browse these folders.  Only user1 can access these folders when he is logged in to his profile.

Is there any way where I can access these files/folders when I am logged in to the file server as Administrator?

Hope my question is clear.  Appreciate any help you can extend.

Thank you.
0
Comment
Question by:bongets
  • 4
  • 3
8 Comments
 
LVL 7

Expert Comment

by:Antzs
ID: 41890910
If the Administrator do not have the rights, you wont be able to access the files/folders.  But being the Administrator, you can always take ownership rights and grant yourself access.

Do take note that, by taking ownership you will remove all other rights which is currently assigned to the file/folders.
0
 

Author Comment

by:bongets
ID: 41890917
Thank you for the comment.  This means that taking ownership is not the best solution because i don't want to removed the rights of the owners of these files/folders.

My only reason of wanting to access their folders is i want to create a batch file that will delete all the files older that 1 year.

I believe that when i run this batch file i will only be able to delete all the other folders except for the files/folders under this /home directory.

any idea how will i do that?

Thank you.
0
 
LVL 7

Expert Comment

by:Andy
ID: 41891114
Hi, taking ownership should not destroy the current permissions on the folder. I;ve done this a few times without issues. However, it may depend on the server family.

To be on the safe side, you might prefer to use the command-line tool, takeown, instead of the GUI tools. This tool definitely won't change the permissions.

Try this article for more information regarding command line:
http://superuser.com/questions/356295/how-do-i-give-administrators-access-to-a-folder-without-destroying-current-permi
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:bongets
ID: 41892422
Hi,

I tried this command TAKEOWN /A /R /F e:\Home\Folder and I was asked with the below question.

Do you want to replace the directory permissions with permissions granting you full control ("Y" for YES, "N" for NO, "C" for CANCEL)?

I selected "N" so that I can take the ownership but not destroy the permissions. Then I went to the security option in GUI to give permission to administrator.  however, it is still giving me the access denied in getting the permission.

did I do it wrong or did i missed something?

Thanks.
0
 
LVL 7

Expert Comment

by:Andy
ID: 41892549
Are you now the owner of the folder?
0
 
LVL 7

Accepted Solution

by:
Andy earned 500 total points
ID: 41892550
If you now have ownership, you can use icacls

icacls c:\folder /grant administrators:f /t

The article below shows the screenshots for this:
https://www.experts-exchange.com/articles/17526/Windows-File-Server-Folder-ownership-problems-and-resolution.html
0
 

Author Comment

by:bongets
ID: 41895372
Thank you.  

I was able to use icacls c:\folder /grant administrators:f /t

but it seems that i have to do it to all of the sub-folders.

from the link you sent i was also trying the subinacl but can't seem to make it work :(
0
 
LVL 7

Expert Comment

by:Andy
ID: 41895491
Hi,

icacls is a great tool  but yeah a pain for subfolders, might be quicker to list all folders and use a batch file.
Good luck!!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question