Solved

Home folder in File server

Posted on 2016-11-16
8
37 Views
Last Modified: 2016-11-21
When I create a user in my AD, it creates a profile in my file server.

Ex.

I created a user named user1

In my file server, there is a shared folder where a profile is created.

\\fileserver\home\user1

under user1 profile it has

Documents
Desktop
Downloads
Pictures

When I am logged in as Administrator in the fileserver itself.  It always gives me an "access denied" error when I try to browse these folders.  Only user1 can access these folders when he is logged in to his profile.

Is there any way where I can access these files/folders when I am logged in to the file server as Administrator?

Hope my question is clear.  Appreciate any help you can extend.

Thank you.
0
Comment
Question by:bongets
  • 4
  • 3
8 Comments
 
LVL 5

Expert Comment

by:Antzs
Comment Utility
If the Administrator do not have the rights, you wont be able to access the files/folders.  But being the Administrator, you can always take ownership rights and grant yourself access.

Do take note that, by taking ownership you will remove all other rights which is currently assigned to the file/folders.
0
 

Author Comment

by:bongets
Comment Utility
Thank you for the comment.  This means that taking ownership is not the best solution because i don't want to removed the rights of the owners of these files/folders.

My only reason of wanting to access their folders is i want to create a batch file that will delete all the files older that 1 year.

I believe that when i run this batch file i will only be able to delete all the other folders except for the files/folders under this /home directory.

any idea how will i do that?

Thank you.
0
 
LVL 6

Expert Comment

by:Andy
Comment Utility
Hi, taking ownership should not destroy the current permissions on the folder. I;ve done this a few times without issues. However, it may depend on the server family.

To be on the safe side, you might prefer to use the command-line tool, takeown, instead of the GUI tools. This tool definitely won't change the permissions.

Try this article for more information regarding command line:
http://superuser.com/questions/356295/how-do-i-give-administrators-access-to-a-folder-without-destroying-current-permi
0
 

Author Comment

by:bongets
Comment Utility
Hi,

I tried this command TAKEOWN /A /R /F e:\Home\Folder and I was asked with the below question.

Do you want to replace the directory permissions with permissions granting you full control ("Y" for YES, "N" for NO, "C" for CANCEL)?

I selected "N" so that I can take the ownership but not destroy the permissions. Then I went to the security option in GUI to give permission to administrator.  however, it is still giving me the access denied in getting the permission.

did I do it wrong or did i missed something?

Thanks.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 6

Expert Comment

by:Andy
Comment Utility
Are you now the owner of the folder?
0
 
LVL 6

Accepted Solution

by:
Andy earned 500 total points
Comment Utility
If you now have ownership, you can use icacls

icacls c:\folder /grant administrators:f /t

The article below shows the screenshots for this:
https://www.experts-exchange.com/articles/17526/Windows-File-Server-Folder-ownership-problems-and-resolution.html
0
 

Author Comment

by:bongets
Comment Utility
Thank you.  

I was able to use icacls c:\folder /grant administrators:f /t

but it seems that i have to do it to all of the sub-folders.

from the link you sent i was also trying the subinacl but can't seem to make it work :(
0
 
LVL 6

Expert Comment

by:Andy
Comment Utility
Hi,

icacls is a great tool  but yeah a pain for subfolders, might be quicker to list all folders and use a batch file.
Good luck!!
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
Synchronize a new Active Directory domain with an existing Office 365 tenant
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now