Re: How to set this Folder security



If you do not want Group A to be able to delete the Magic folder, you have to make sure they cannot delete subfolders and files in the QA folder AND you need to take away (or deny) their right to delete the Magic folder itself. Furthermore, you should then give Group A the permission, on Magic, to delete subfolders and files.

Some things to note here:
- Denying Delete folders and subfolders on the QA dir will not, in itself, prevent them from deleting the Magic folder. You need to deny delete on that folder as well.
- Denying Delete on the Magic folder will not, in itself, prevent them from deleting that folder.
- Denying Delete folders and subfolders on the QA dir will not prevent them from deleting any other folders in the QA dir where they have the permissions to delete them.

As Roger stated, you can remove the inheritance from parent folders, or you can just add what you need on the folder itself, since permissions set directly on an object will normally take precedence over inherited permissions. However, when I start getting creative with file permissions, I prefer not to inherit from the parent.


Mark Burnett





"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message news:OJDYupO6GHA.4404@xxxxxxxxxxxxxxxxxxxx:

Since on the QA parent folder of Magic you have explicitly
stated that GroupA can delete folders within QA you need
to "override" that. There are two ways. First, my preferred,
is to go into the NTFS permissions on Magic and in the
Advanced view uncheck the spec for it to inherit permissions.
You would probably want to select Copy of permissions, and
then edit these so that the GroupA grant is like that you had
granted on QA. The other route would be to leave Magic
inheriting permissions but to add a new ACE that Denies
GroupA Delete for This folder only.
I prefer the first way as use of Deny can become complicated
all too fast, especially if the Deny gets inherited onto substructure
and/or files.
"cisconoobie via WinServerKB.com" <u26219@uwe> wrote in message
news:6755825a42dcf@xxxxxx

>I have a folder named QA that is inheriting the following permissions:
>
> Domain Admins - Full
> Authenticated Users - Read & Execute
>
> I manually add Group A for read, execute and special permission ( I
enable
> delete subfolders and files) I make sure Delete is unchecked.
>
> Now I create "Magic" folder inside QA and I want to make sure Group A
has
> Delete priviledges for subfolders and files of Magic but I dont want
group
> A
> from deleting the "Magic" Folder.
>
> How do I do that?
>
> --
> Message posted via WinServerKB.com
>
http://www.winserverkb.com/Uwe/Forums.aspx/windows-server-security/20061
0/1
>

.



Relevant Pages

  • Re: Default permissions for the "Default User" account folder
    ... > I gather that Windows uses the permissions from this ... > folder when adding new user accounts. ... > Full - Administrators - This folder, subfolders, and files ... and have created several templates ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to set folder private?
    ... If the check boxes under Permissions for user or group are shaded or if the ... then the file or folder has inherited ... permissions from the parent folder. ... are created in the folder inherit these permissions. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: NTFS - Restrict file deletion
    ... NTFS permissions are XP standard. ... File is in folder. ... the Admin from deleting a file or folder. ... check on "Inherit from Parent...", click Apply, click ...
    (microsoft.public.windowsxp.general)
  • Re: NTFS - Restrict file deletion
    ... NTFS permissions are XP standard. ... File is in folder. ... the Admin from deleting a file or folder. ... check on "Inherit from Parent...", click Apply, click ...
    (microsoft.public.windowsxp.general)
  • Re: Why do some folders/registry keys have 2 permissions instead of 1?
    ... > I'm trying to write a script that will compare permissions for a large ... But if you check the folder or registry key's ... > group/user when it only needed to save one ACE. ... > gives Full Control to myuser for subfolders and files, ...
    (microsoft.public.win2000.general)

Quantcast