Re: User Folders created by the system

From: Infotech (adsf)
Date: 02/11/05


Date: Fri, 11 Feb 2005 08:26:44 -0600

Thanks! I was afraid I would have to change them on the parent folder then
go a reset all the other permissions. Thankfully that's not the case.

Thanks.

--
Infotech
"Stuart Mackie [MCSE MCSA]" <newsgroups@--REMOVE_THIS-NO_SPAM--stu.uk.com> 
wrote in message news:ek2GKE9DFHA.2756@TK2MSFTNGP15.phx.gbl...
> Hi.  When using the AD users and computers console the default behaviour 
> in Win2k3 is to inherit parent permissions. To make sure future users have 
> the correct permissions without having to manually adjust them you will 
> need to alter your parent folder permissions.  An example of permissions 
> you could use would be:
>
> 'Parent Folder' NTFS Permissions
>    System - Full Control
>    Domain users - Read & Execute (see below before applying)
>                            List Folder Contents
>                            Read
>    Domain Admins - Full Control (This depend on company policy)
>
> Before Accepting/Applying the above changes, click Advanced, select the 
> Domain Users entry, click Edit and set Apply onto to 'This Folder and 
> Files' (i.e. NOT This Folder, Subfolder and Files).
> Adjust the above permissions to accomodate your company policy i.e. Admin 
> permissions on user home folders etc.
>
>
> Share Permissions
>    Domain Users - Full Control
>    Domain Admins - Full Control
>
>
> When you now create a new user, for the home folder section use 
> \\fileserver\\users\\%username%  The AD console will create the %username% 
> folder which will inherit the parent permissions.  Since the Domain Users 
> permission only applies to the Parent folder only, this permission will 
> not be inherited and the AD console will add the Full Control permission 
> for the user.
> "Infotech" <adsf> wrote in message 
> news:u3Tvcg8DFHA.2608@TK2MSFTNGP10.phx.gbl...
>>I have local users Home Folder (in User properties) set to connect to a 
>>share on our file server. Microsoft recommends using 
>>\\fileserver\users\userfolder.  I decided to do that for all our users. 
>>The security problem arises when the system creates the folder it inherits 
>>file permissions from the parent folder, adding "Authenticated Users" 
>>group with Read permission on every user folder it creates inside "Users". 


Relevant Pages

  • Re: local users and groups
    ... following error message occurs; "access to the \\servername has been ... group on the AD and the domain users group is in the users group of the ... If you look at the actual folder that is shared on server3, right click the folder name, choose properties, then choose Sharing tab. ... What groups/users do you see in there, and what are their share permissions? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The fact that the tech support is based in India has nothing to do with the ... If so you may want to leave this folder alone. ... down to all children folders because i can set those permissions to ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Unable to delete orphaned 1.5 GB System Restore folder
    ... The only computers i fix are my own. ... If so you may want to leave this folder alone. ... it includes all subdirectories with inherited permissions. ... try deleting from the command line using system by using the AT ...
    (microsoft.public.windowsxp.security_admin)
  • RE: no OWA
    ... have the correct permissions was the "inetpub" folder. ... Correct the settings in IIS: ... click to check the "Hide All Microsoft Services" ...
    (microsoft.public.windows.server.sbs)