Re: Permissions question

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 08/23/05


Date: Tue, 23 Aug 2005 00:27:35 -0500

The users need full control permissions to their folder and be owner of the
folder. The users group should also full control permissions to the share.
You right click a folder, select properties - security to manage ntfs
permissions. Anyone who knows the path to the share can see the share
contents if they have at least read permissions to the share but not access
a folder in a share unless they have permissions to the folder.. There is an
exception with SP1 if you are using access based enumeration as shown in the
second link below. The first link below may help you in determining
permissions needed for your users.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/management/user01.mspx
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/BookofSP1/f04862a9-3e37-4f8c-ba87-917f4fb5b42c.mspx
http://support.microsoft.com/default.aspx?kbid=300691 --- how to configure
for secure file access.

"Kim K" <KimK@discussions.microsoft.com> wrote in message
news:083258B2-859A-4C14-934E-67B0E9CA28D5@microsoft.com...
>I have a 2003 server that I am moving all users from another server to the
>03
> one. I have created the users name and $ and shared it out. I have
> changed
> the home path in active directory to reflect the new path of the users
> folder. I can log into the domain as the user and map the users folder.
>
> I am not able to save to this folder and know it is a permission issue but
> due to lack of time and not enough research I was a bit reluctant to move
> forward. If I right click on the users folder go to Sharing and security
> I
> can see the group and users names and the access rights. There is also an
> advanced feature.
>
> If I right click on the users folder and go to properties (I think as I am
> not right in front of it) I can get to a second different permissions menu
> where I can select the users and check the name (apparently verified in
> active directory).
>
> My question is where do I set the permissions for the user and also add
> the
> tech person with admin rights? I hope I am on the right path to geting
> this
> set up correctly.
>
> Am I also correct in believeing that anyone who would know that path can
> map
> to a shared folder but with the correct permissions can not read or see
> any
> of the material in the users folder?
> --
> Thanks in advance,
> Kim



Relevant Pages

  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The fact that the tech support is based in India has nothing to do with the ... If so you may want to leave this folder alone. ... down to all children folders because i can set those permissions to ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The only computers i fix are my own. ... If so you may want to leave this folder alone. ... it includes all subdirectories with inherited permissions. ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • Re: share folder permissions
    ... B Group -> Read only permissions over ALL the sub-folders and files ... List Folder Contents, Read, and Write. ... Usually we just add Domain Admins FC, and Authenticated Users, Change. ... Then whatever is set in the folder structure using NTFS will dicate their effective permissions. ...
    (microsoft.public.windows.server.networking)
  • Re: Default NTFS permissions too liberal on newly created volumes
    ... A rule of thumb that I use is when making a new folder off the root of the drive, to be used as a share, I remove the inheritance ... > read-only permissions via a certain group. ... > I looked at the other servers that we've built and all have the same all-too-liberal permission settings for the USERS group. ...
    (microsoft.public.windows.server.security)