Click here to get back home

Permission Issue

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Permission Issue Scott 09-28-2005
`--> Re: Permission Issue Roger Abell [MV...10-02-2005
Posted by Scott on September 28, 2005, 10:55 am
Please log in for more thread options
Hi all,
I have a weird problem with a freshly installed W2k server. It is
not running as a domain controller, and is just a member of a workgroup. I
have a sub-folder on the hard-drive which I am putting user folders in for
network clients to store files on. The problem is as follows:

Lets say there are users A,B and C.
I have created three folders - c:\data\A
c:\data\B
c:\data\C

On each of the three folders, the Share, and security permissions are set to
'Full Control', for both 'Administrator' and the applicable User.

With that said, I would expect 'Administrator' to have full access to all 3
folders, and each user to only have access to their relevant folder.
Unfortunately, they can ALL access ALL 3 of the folders (shares) across the
network.

They are NOT members of the Administrator group, only the 'Users' group.

The parent data folder I have set to 'Full Control' for both 'Administrator'
and the 'Users' group, and unticked 'Inherit permissions' etc.

What am I doing wrong here???

Any help would be greatly appreciated
Scott




Posted by Steven L Umbach on September 27, 2005, 10:19 pm
Please log in for more thread options
First off check the ntfs permissions on the root/drive folder to make sure
that the everyone group does not have full control. If it does change it to
read/list/execute. For the parent data folder give users group read/list
permissions and then give each user full control for their folder to see if
that helps and verify that only administrator and the user account is
included in the ntfs permissions and also check the advanced page for
properties/security to check special permissions. When you set permissions
on the main security page of a folder that will set security for folder,
subfolder, and files as seen in the advanced page where you cans see or edit
permissions for a user/group and select the apply onto box. --- Steve


> Hi all,
> I have a weird problem with a freshly installed W2k server. It is
> not running as a domain controller, and is just a member of a workgroup. I
> have a sub-folder on the hard-drive which I am putting user folders in for
> network clients to store files on. The problem is as follows:
>
> Lets say there are users A,B and C.
> I have created three folders - c:\data\A
> c:\data\B
> c:\data\C
>
> On each of the three folders, the Share, and security permissions are set
> to 'Full Control', for both 'Administrator' and the applicable User.
>
> With that said, I would expect 'Administrator' to have full access to all
> 3 folders, and each user to only have access to their relevant folder.
> Unfortunately, they can ALL access ALL 3 of the folders (shares) across
> the network.
>
> They are NOT members of the Administrator group, only the 'Users' group.
>
> The parent data folder I have set to 'Full Control' for both
> 'Administrator' and the 'Users' group, and unticked 'Inherit permissions'
> etc.
>
> What am I doing wrong here???
>
> Any help would be greatly appreciated
> Scott
>




Posted by Roger Abell [MVP] on October 2, 2005, 8:10 am
Please log in for more thread options
On the parent folder, when you unticked "Inherit permissions" you
are stating that inheritable settings should not flow down onto that
parent folder from above. That does not control the flow onto the
child folders. You would need to either that selection on each of
the child folders, or, at the parent folder use the advanced dialog's
Edit button to change the grant to Users from applying to This folder,
subfolders, and Files to only This folder and files.

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
> Hi all,
> I have a weird problem with a freshly installed W2k server. It is
> not running as a domain controller, and is just a member of a workgroup. I
> have a sub-folder on the hard-drive which I am putting user folders in for
> network clients to store files on. The problem is as follows:
>
> Lets say there are users A,B and C.
> I have created three folders - c:\data\A
> c:\data\B
> c:\data\C
>
> On each of the three folders, the Share, and security permissions are set
> to 'Full Control', for both 'Administrator' and the applicable User.
>
> With that said, I would expect 'Administrator' to have full access to all
> 3 folders, and each user to only have access to their relevant folder.
> Unfortunately, they can ALL access ALL 3 of the folders (shares) across
> the network.
>
> They are NOT members of the Administrator group, only the 'Users' group.
>
> The parent data folder I have set to 'Full Control' for both
> 'Administrator' and the 'Users' group, and unticked 'Inherit permissions'
> etc.
>
> What am I doing wrong here???
>
> Any help would be greatly appreciated
> Scott
>




Similar ThreadsPosted
File Permission Issue Help! September 9, 2005, 8:05 am
Permission issue: Accessing AzMan store in ADAM from ASP.NET worker process March 2, 2007, 4:09 pm
Spontaneous permission changes-How?Why? September 23, 2005, 2:06 pm
Adobe permission January 4, 2006, 2:03 pm
NTFS Permission April 21, 2006, 10:04 am
File Permission June 14, 2008, 5:36 am
Restart service permission June 8, 2005, 3:34 pm
Giving users permission to an MMC June 23, 2005, 11:01 am
Logon as a Batch Job Permission December 6, 2005, 3:12 am
NTFS permission problem March 31, 2006, 11:36 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap