Re: Permissions on 'My documents'



Hi Roger,
Got the solution. We need to use the ‘File system’ setting. In the
GPO related to the concerned users, go to
Computer Configuration->Windows setting->Security setting->’File
System’-> Right click on ‘File system’-> Click on ‘Add File’. Select C: drive.
Add the user to the list and modify the security setting to ‘Read and
execute’. In this way, the user will only have read access on C drive.

To provide ‘modify’ access to the user on his profile, go to the GPO
Computer Configuration->Windows setting->Security setting->File system’->
Right click on ‘File system’-> Click on ‘Add File’. Browse to ‘Administrator’
profile in ‘Document and settings’ folder this time. [We assume that you are
using ‘Administrator’ account to modify GPO settings]

Add user to the security list and modify the security setting to ‘Modify’.
This way the users will have ‘write’ and ‘modify’ access on their profile.

Hence the users will be able to create files and folders only on their
profile.

Regards
Ram


"Roger Abell [MVP]" wrote:

It at first seems simple to do so, using any of a number of ways (a startup
script that uses xcacls, or applies a security conf template).
However, test, test, test as the normal settings would cause a propagation
onto the substructure, but what you want to do is to leave all existing
spots
where inheritance is block as they are, changing only the ACL on the root.

"Ram" <Ram@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0BEFAA8B-8788-4C77-897F-248478776900@xxxxxxxxxxxxxxxx
Thanks Roger.
But how can I restrict users from creating folders on the root through
GPO.

Regards
Ram

"Roger Abell [MVP]" wrote:

Ram,
From your post's implications it seems you are considering placing a
Deny of Write over all hard disk on a user's system, or or otherwise
effecting removal of all grants of Write - with the exception of their
My Documents.

Any account needs the ability to write in some areas outside of their
My Documents.

If you are using an XP client system you will find that users that have
only limited accounts are fairly much restricted to only what is needed,
except that they have a grant at the root of the install drive allowing
them to make new folders at that level and have full control of them
(change the Users grants so read/execute is the only one, removing
the two special grants that allow creates, and remove the Creator
Owner grant, and DO NOT use the checkbox that makes the change
over all that is contained).
If there are other partitions besides the install partition, adjust those
as desired. You do not need to be so careful with those others as
one MUST BE CAREFUL with the install partition.

"Ram" <Ram@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:36469A3D-FEB8-40EF-8BC4-D2ED2CEA377F@xxxxxxxxxxxxxxxx
Dear All,
How can I provide 'write' access to users on their 'My Documents'
folder, at the same time denying them 'write' access on their local
drive?
Can this be possible without redirecting 'My documents' to a
network
folder?

Regards
Ram







.



Relevant Pages

  • Network Shared Files/UNC
    ... issues regarding our network security. ... GPO settings are not inherited from the domain GPO ... folders of our servers by just running Notepad and going ... another way of tightening security so that the Servers are ...
    (microsoft.public.win2000.active_directory)
  • Solution for V6 Trouble
    ... - temporary deactivate the GPO that enforces automatic updates on client ... - Make a backup copy of all files and folders under ...
    (microsoft.public.windowsupdate)
  • Re: Terminal Svs. Roaming Profile
    ... Folders When You Make a Roaming User Profile ... MCSE, CCEA, Microsoft MVP - Terminal Server ... start using a GPO to do this using the Terminal Services ...
    (microsoft.public.windows.terminal_services)
  • Re: GPO not doesnt apply to everyone
    ... It deals with exclsive rights to their folders. ... I have previously created folders that they map to using KIXTART. ... GPO was not working on the users. ... the redirection will be to ...
    (microsoft.public.win2000.group_policy)
  • Re: AutoArchive Inbox Group Policy
    ... individual folder archive settings cannot be set with GPO. ... Sue Mosher, Outlook MVP ... The policy resulted in the Archive Folders being generated on the ... but not the Inbox and Inbox subfolders. ...
    (microsoft.public.outlook.installation)