Click here to get back home

NTFS Drop Folder - Blocking Owner from changing files

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
NTFS Drop Folder - Blocking Owner from changing files FB 05-19-2008
Get Chitika Premium
Posted by Roger Abell [MVP] on May 20, 2008, 5:58 am
Please log in for more thread options
What share level permissions are you using ?
They should not be at default, but should specify only the
most you want used and only by what groups/accounts.
To assist with tightening your NTFS permissions people
here probably need to know/see what you are now trying
to use (ex. output of xcacls)

Roger

>
> I have a complex Folder Tree with several Files/Folders and the customer
> wants to create a proccess where the user puts ("drops") the file in the
> folder tree and after that, the file must be innacessible.
>
> Now is working with Write-Only NTFS Permissions on the folder tree
>
> But the owner of the file can modify the file, and i don´t wanna that. I
> want a true "drop" folder where once the file is "droped" in the folder,
> the
> file must be innacessible for the owner too
>
> i´m not talking about FTP, i´m talking about a regular Share/NTFS Folder
> Tree



Posted by FB on May 20, 2008, 9:03 am
Please log in for more thread options

Tanks for the answer, here come clarifications about the question:

1) Creator Owner is NOT on the ACLs of the Shared Folder/NTFS Folder
2) Win2003 STD SP1 64-Bits, Clients with XP SP2+Patches
3) Shared Folder permissions are Full Control because is a Huge Tree, with
90.000 files in one share and more than 100 Local Groups to control the use
of the folder
4) ABE is an option, but i want to avoid it because will affect ("visually"
talking) other users
5) Shared Folder is Everyone/Full Control and NTFS Folder is Everyone Read
and a lot of other permissions to control teh access on more than 3.000
folders



"FB" wrote:

>
> I have a complex Folder Tree with several Files/Folders and the customer
> wants to create a proccess where the user puts ("drops") the file in the
> folder tree and after that, the file must be innacessible.
>
> Now is working with Write-Only NTFS Permissions on the folder tree
>
> But the owner of the file can modify the file, and i don´t wanna that. I
> want a true "drop" folder where once the file is "droped" in the folder, the
> file must be innacessible for the owner too
>
> i´m not talking about FTP, i´m talking about a regular Share/NTFS Folder Tree

Posted by Roger Abell [MVP] on May 20, 2008, 9:33 pm
Please log in for more thread options
Given your scenario, i.e. number of groups involved, would
change of share permissions from Everyone Full to Everyone
Change (possibly plus Administrators Full) be sufficient for
all intended accesses?
The owners can exercise their ownership and change permissions
as long as you allow those parts of Full (change permissions) to be
used over the network.

Roger

>
> Tanks for the answer, here come clarifications about the question:
>
> 1) Creator Owner is NOT on the ACLs of the Shared Folder/NTFS Folder
> 2) Win2003 STD SP1 64-Bits, Clients with XP SP2+Patches
> 3) Shared Folder permissions are Full Control because is a Huge Tree, with
> 90.000 files in one share and more than 100 Local Groups to control the
> use
> of the folder
> 4) ABE is an option, but i want to avoid it because will affect
> ("visually"
> talking) other users
> 5) Shared Folder is Everyone/Full Control and NTFS Folder is Everyone Read
> and a lot of other permissions to control teh access on more than 3.000
> folders
>
>
>
> "FB" wrote:
>
>>
>> I have a complex Folder Tree with several Files/Folders and the customer
>> wants to create a proccess where the user puts ("drops") the file in the
>> folder tree and after that, the file must be innacessible.
>>
>> Now is working with Write-Only NTFS Permissions on the folder tree
>>
>> But the owner of the file can modify the file, and i don´t wanna that. I
>> want a true "drop" folder where once the file is "droped" in the folder,
>> the
>> file must be innacessible for the owner too
>>
>> i´m not talking about FTP, i´m talking about a regular Share/NTFS Folder
>> Tree



Posted by FB on May 23, 2008, 4:15 pm
Please log in for more thread options
I´ll try this, i´m afraid to solve this problem am start a new one, but i
think is better than write a Script to give ownership of the files once a day


"Roger Abell [MVP]" wrote:

> Given your scenario, i.e. number of groups involved, would
> change of share permissions from Everyone Full to Everyone
> Change (possibly plus Administrators Full) be sufficient for
> all intended accesses?
> The owners can exercise their ownership and change permissions
> as long as you allow those parts of Full (change permissions) to be
> used over the network.
>
> Roger
>
> >
> > Tanks for the answer, here come clarifications about the question:
> >
> > 1) Creator Owner is NOT on the ACLs of the Shared Folder/NTFS Folder
> > 2) Win2003 STD SP1 64-Bits, Clients with XP SP2+Patches
> > 3) Shared Folder permissions are Full Control because is a Huge Tree, with
> > 90.000 files in one share and more than 100 Local Groups to control the
> > use
> > of the folder
> > 4) ABE is an option, but i want to avoid it because will affect
> > ("visually"
> > talking) other users
> > 5) Shared Folder is Everyone/Full Control and NTFS Folder is Everyone Read
> > and a lot of other permissions to control teh access on more than 3.000
> > folders
> >
> >
> >
> > "FB" wrote:
> >
> >>
> >> I have a complex Folder Tree with several Files/Folders and the customer
> >> wants to create a proccess where the user puts ("drops") the file in the
> >> folder tree and after that, the file must be innacessible.
> >>
> >> Now is working with Write-Only NTFS Permissions on the folder tree
> >>
> >> But the owner of the file can modify the file, and i don´t wanna that. I
> >> want a true "drop" folder where once the file is "droped" in the folder,
> >> the
> >> file must be innacessible for the owner too
> >>
> >> i´m not talking about FTP, i´m talking about a regular Share/NTFS Folder
> >> Tree
>
>
>

Posted by neo [mvp outlook] on May 20, 2008, 11:28 pm
Please log in for more thread options
Would it help if I supplied an example of what to set share and ntfs
permissions to allow a single group of users to write once and not be able
to change/read/delete in any way?

>
> Tanks for the answer, here come clarifications about the question:
>
> 1) Creator Owner is NOT on the ACLs of the Shared Folder/NTFS Folder
> 2) Win2003 STD SP1 64-Bits, Clients with XP SP2+Patches
> 3) Shared Folder permissions are Full Control because is a Huge Tree, with
> 90.000 files in one share and more than 100 Local Groups to control the
> use
> of the folder
> 4) ABE is an option, but i want to avoid it because will affect
> ("visually"
> talking) other users
> 5) Shared Folder is Everyone/Full Control and NTFS Folder is Everyone Read
> and a lot of other permissions to control teh access on more than 3.000
> folders
>
>
>
> "FB" wrote:
>
>>
>> I have a complex Folder Tree with several Files/Folders and the customer
>> wants to create a proccess where the user puts ("drops") the file in the
>> folder tree and after that, the file must be innacessible.
>>
>> Now is working with Write-Only NTFS Permissions on the folder tree
>>
>> But the owner of the file can modify the file, and i don´t wanna that. I
>> want a true "drop" folder where once the file is "droped" in the folder,
>> the
>> file must be innacessible for the owner too
>>
>> i´m not talking about FTP, i´m talking about a regular Share/NTFS Folder
>> Tree



Similar ThreadsPosted
HOWTO: Creating a Drop-Only Shared Folder June 9, 2008, 3:05 pm
EFS blocking users from accessing their encrypted files June 6, 2007, 10:33 am
Cleaning Up Files that are Missing NTFS Permissions March 20, 2006, 11:54 am
Folder and Files Security October 3, 2006, 1:46 pm
NTFS , folder permissions ! Need Help January 4, 2006, 11:51 am
Using CREATOR GROUP for files/folder July 11, 2005, 10:43 am
Share folder and NTFS permission April 10, 2008, 6:47 pm
deny create folder but allow create files June 16, 2005, 12:08 pm
permissions on subfolders with drag and drop July 18, 2007, 3:16 pm
Using CREATOR OWNER February 5, 2007, 2:38 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap