Click here to get back home

Home directory permission soup

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Home directory permission soup Rickard 10-24-2007
Posted by Rickard on October 24, 2007, 11:19 am
Please log in for more thread options
I've been searching for the correct permissions to put on a shared
folder that contains user home directories in our server2003/xp
environment. We also do folder redirection of Application Data into
the home directory via a domain level group policy.

http://technet2.microsoft.com/windowsserver/en/library/a1b7ce04-708b-4145-830a-cadfc003acd31033.mspx?mfr=true

The above article contains a table under "NTFS permissions required
for the root folder" that lists suggested permissions for the root
folder into which you do folder redirection, but that's not quite what
we have. We have a folder containing home directories and then
Application Data is redirected into the home directory. In other
words, home directories are located in \srvxxx\home and Application
Data is redirected into \srvxxx\home\%username%\Application Data.
We're curious about which permissions to set on the root folder in
which we store home directories. Currently, we have the following
permissions set on \srvxxx\home:

Share permissions - Everyone - Full control

Creator/owner - Full Control - This folder, subfolders, and files
Administrators - Full Control - This folder, subfolders, and files
System - Full Control - This folder, subfolders, and files
Authenticated Users - List Folder/Read Data, Create Folders/Append
Data - This folder only

This almost works the way we want it. The home directory is created
automatically and virtually all interaction with the home directory as
well as the redirected application data folder (inside the home dir)
works. The directory is also mapped to H: according to what we specify
in the user properties in Active Directory. However, whenever we try
to launch Office on a client, we get an error (1324) stating that
"Application Data" contains an illegal character. After many hours of
trial and error, I have been able to determine that in order for
Office to start up properly, we need to add the "Read Attributes"
permission to the root home directory (\srvxxx\home). If we do, then
Office works like a charm. However, with "Read Attributes" enabled,
users are able to list the folder contents of \srvxxx\home and we
definitely don't want that. Remove "Read Attributes" and they get a
permission error (good), but then Office breaks.

Can anyone point me in the right direction regarding this permission
soup? Everywhere I look, people recommend different settings. This is
driving me crazy!

Cheers,
Rickard


Posted by Anthony on October 24, 2007, 12:12 pm
Please log in for more thread options
Hi Rickard,
I _think_ it will work to change the "Read Attributes" to "Traverse" but it
is a while since I tested it.
You can also use Home$ to deter casual browsing.
Finally, Windows up to R2 is relaxed about users being able to see folders
they don't have access to, but R2 provides ABE if you want to explicity
prevent it,
Hope that helps.
Anthony, http://www.airdesk.co.uk


> I've been searching for the correct permissions to put on a shared
> folder that contains user home directories in our server2003/xp
> environment. We also do folder redirection of Application Data into
> the home directory via a domain level group policy.
>
>
http://technet2.microsoft.com/windowsserver/en/library/a1b7ce04-708b-4145-830a-cadfc003acd31033.mspx?mfr=true
>
> The above article contains a table under "NTFS permissions required
> for the root folder" that lists suggested permissions for the root
> folder into which you do folder redirection, but that's not quite what
> we have. We have a folder containing home directories and then
> Application Data is redirected into the home directory. In other
> words, home directories are located in \srvxxx\home and Application
> Data is redirected into \srvxxx\home\%username%\Application Data.
> We're curious about which permissions to set on the root folder in
> which we store home directories. Currently, we have the following
> permissions set on \srvxxx\home:
>
> Share permissions - Everyone - Full control
>
> Creator/owner - Full Control - This folder, subfolders, and files
> Administrators - Full Control - This folder, subfolders, and files
> System - Full Control - This folder, subfolders, and files
> Authenticated Users - List Folder/Read Data, Create Folders/Append
> Data - This folder only
>
> This almost works the way we want it. The home directory is created
> automatically and virtually all interaction with the home directory as
> well as the redirected application data folder (inside the home dir)
> works. The directory is also mapped to H: according to what we specify
> in the user properties in Active Directory. However, whenever we try
> to launch Office on a client, we get an error (1324) stating that
> "Application Data" contains an illegal character. After many hours of
> trial and error, I have been able to determine that in order for
> Office to start up properly, we need to add the "Read Attributes"
> permission to the root home directory (\srvxxx\home). If we do, then
> Office works like a charm. However, with "Read Attributes" enabled,
> users are able to list the folder contents of \srvxxx\home and we
> definitely don't want that. Remove "Read Attributes" and they get a
> permission error (good), but then Office breaks.
>
> Can anyone point me in the right direction regarding this permission
> soup? Everywhere I look, people recommend different settings. This is
> driving me crazy!
>
> Cheers,
> Rickard
>



Similar ThreadsPosted
Home directory permissions. What to set? September 26, 2006, 12:07 am
Looking for best practices for setting up secure user home directory file structure October 6, 2006, 8:47 pm
Howto : programatically give NTAUTHORIRTY\Network Service account write permission on a directory August 4, 2005, 9:38 pm
auditing active directory not working properly directory serviceaccess October 21, 2005, 7:47 pm
Linking PKI directory accounts with Active Directory? February 11, 2007, 5:29 am
Home Business Opportunity October 8, 2005, 10:54 am
home network problem March 23, 2006, 1:21 am
User Home Folder August 4, 2006, 10:18 am
Windows Home Server February 6, 2008, 5:28 am
Help with security rights for Home directories June 7, 2005, 4:48 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap