Re: ACLs - Users with READ can MOVE a whole folder?
- From: "Gerry Hickman" <gerry666uk@xxxxxxxxxxxxxxxx>
- Date: Thu, 12 Apr 2007 09:55:00 +0100
Hi Roger,
Yes, it looks like the problem is related to users having full control
instead of modify only. In general, all our shares are set up for modify
only, but this one was left over from years ago and I never got round to
changing it!
Thanks for solving it.
--
Gerry Hickman - (London UK)
"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:eaMaUHMfHHA.5044@xxxxxxxxxxxxxxxxxxxxxxx
You are probably seeing an effect from the so-called "hidden child delete"sub-folder
that is part of a full control grant as is a requirement for Posix
compliance.
Consider providing the Users group with Modify on U: or Modify and also
Change Permissions and Take Ownership if you do really want them to
have that. IIRC there is a discussion in the resource kit on the child
delete
included in full control.
"Gerry Hickman" <gerry666uk@xxxxxxxxxxxxxxxx> wrote in message
news:%23HVARgEfHHA.4136@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
I have a mapped drive as follows
U:\ (users full)
Shared Docs (users full)
Computer Docs (users Read and Execute)
Other Docs (users full)
In general it works as expected, ordinary users can't put docs into the
"Computer Docs" folder, nor delete them. If they try to move a
itof
"Computer Docs" they get "Access Denied", BUT
If they drag and drop the WHOLE of "Computer Docs" into "Shared Docs",
thoughlets them do it! No questions! I don't understand this because even
deletethey're allowed to COPY the whole folder, I don't see how they can
ait
after. It's as if MOVE by dragging and dropping is not seen as requiring
DELETE operation to complete??
Thanks for any help. This test was done with Win2k clients and servers,
not
sure if the o/s makes any difference.
--
Gerry Hickman - (London UK)
.
- References:
- ACLs - Users with READ can MOVE a whole folder?
- From: Gerry Hickman
- Re: ACLs - Users with READ can MOVE a whole folder?
- From: Roger Abell [MVP]
- ACLs - Users with READ can MOVE a whole folder?
- Prev by Date: Re: ACLs - Users with READ can MOVE a whole folder?
- Next by Date: Re: There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away.
- Previous by thread: Re: ACLs - Users with READ can MOVE a whole folder?
- Next by thread: "the local policy of this system does not permit you to logon interactively"
- Index(es):
Relevant Pages
|
|