Click here to get back home

Locking folders but NOT files. How?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Locking folders but NOT files. How? pishigorbeh 01-05-2007
Posted by pishigorbeh on January 5, 2007, 9:20 am
Please log in for more thread options
Hello.
I know this should be simple but how do I set the permission on a folder
being served by a windows 2003 server such that DOMAIN USERS can create,
append, delete any file but only DOMAIN ADMINS can create or delete folders.
Thanks

Pishi



Posted by Laura E. Hunter [MVP] on January 5, 2007, 12:20 pm
Please log in for more thread options
From the GUI you can go to the Advanced Tab and configure permissions that
will apply to "This folder only", "This folder, sub-folders and files" or
"Files only". Using a combination of these options you can configure much
more granular permissions than by using the pre-canned permissions on the
main Security tab.

To automate the process across multiple servers, you can also use the cacls
command-line utility or vbscript - check out sample scripts from the Technet
Script Repository to get you started.

HTH


--
Laura E. Hunter
Microsoft MVP: Windows Server - Networking
Author: _Active Directory Consultant's Field Guide_
(http://tinyurl.com/7f8ll)
Author: _Active Directory Cookbook, Second Edition_
(http://tinyurl.com/z7svl)

Responses provided as-is; no warranties expressed or implied
> Hello.
> I know this should be simple but how do I set the permission on a folder
> being served by a windows 2003 server such that DOMAIN USERS can create,
> append, delete any file but only DOMAIN ADMINS can create or delete
> folders.
> Thanks
>
> Pishi
>



Posted by Roger Abell [MVP] on January 6, 2007, 1:46 am
Please log in for more thread options
Using the two groups you mentioned, DA and DU, you appear
to want grants (at the root of the structure) of
DA Modify (at default of This folder, subfolders and files)
DU List (at default scoping)
DU Modify scoped to Files only

> Hello.
> I know this should be simple but how do I set the permission on a folder
> being served by a windows 2003 server such that DOMAIN USERS can create,
> append, delete any file but only DOMAIN ADMINS can create or delete
> folders.
> Thanks
>
> Pishi
>



Similar ThreadsPosted
Files and Folders April 3, 2006, 4:40 am
Audit Folders and Files December 5, 2007, 11:11 am
Special Permission for folders and files January 12, 2006, 12:04 pm
Hide folders / files with no access October 4, 2006, 12:10 pm
Audit - Summary of the folders and files November 6, 2006, 8:58 am
Windows 2003 - hide inaccessible files and folders July 28, 2005, 3:31 pm
Read-Only Access to the entire server - everything , not just the Files & Folders October 23, 2005, 8:12 pm
How to let user group member to share files and folders August 26, 2006, 12:16 am
Create a domain account with full access to all files and folders? October 24, 2006, 11:03 am
Is there any utility to recursively delete unknown SIDs from permissions on files/folders? November 3, 2005, 10:17 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap