Re: NTFS Deny not Working STRANGE
From: Phil B (philb_at_talk21.com)
Date: 09/30/05
- Next message: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Previous message: RL: "Re: Folders and permissions"
- Next in thread: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Maybe reply: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 30 Sep 2005 14:32:00 +0100
I had a similar, but not identical issue.
The problem was being caused by the difference between the permissions
accessible: (1) By clicking the 'Permissions' button on the Sharing tab,
and (2) By accessing the Security/Permissions tab.
I found that I couldn't just get away with setting the permissions on
one of the tabs, but they also had to be set in the other place as well.
This has only happened with certain shares/folders however.
Strange is indeed the word.
Elizabeth Strachan wrote:
> To anyone who can help,
>
> I am having the strangest problem with a Windows 2003 Server.
> Long story short we have to let some software developers TS into one of our
> servers but the server also has company data on it that we don't want them to
> access. The data is on a separate partition from anything else. My answer
> was thus:
> 1. Create Domain Local Security Group
> 2. Deny Full Access at the root of the partition to the Group
> 3. Add users to the group.
>
> Normally I would expect this to work but it does not. The deny is supposed
> to override everything else but for some reason it is not working.
>
> Here the strangeness continues:
> If I Logon as the user and double click on the partition it says "No Access"
> as expected but I can then do a D:\Some Folder on it and it all works fine.
> They can then open documents and explore as they like.
>
> I have gone into Advanced and reset permissions on files and folders. I
> have gone into effective permissions and when I choose the group it says no
> permission, when I choose one of the users it says Full Control. I have
> removed and re-added the group to the user. The user has no special user
> rights - we made a special group that had TS access but no ability to
> shutdown/restart etc. so they are not system administrators.
>
> The server is Windows 2003 SP1 and the only thing special about it is that
> we have loaded the patch to hide folders via shares that users have no
> permissions to.
>
> I can't seem to find anyone else with the same problem so I am at a loss to
> fix it? I can specifically deny it for that specific user and it works but
> this will create us a lot of maintenance in the long run.
>
> Does anyone have any ideas?
>
> Sincerely,
> Elizabeth
- Next message: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Previous message: RL: "Re: Folders and permissions"
- Next in thread: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Maybe reply: Steven L Umbach: "Re: NTFS Deny not Working STRANGE"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]