Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Folder/Directory security

Status
Not open for further replies.

Cogen

Programmer
Feb 12, 2003
76
CA
I'm not sure if the settings that I have changed in the folder security are the problem, but I'm having a problem with accessing folders on my network server.
I have a directory called "Staff", and all of the staff members have their own directory under that (example: John Smith has a directory - Staff/jsmith/). In that example, I want John Smith to have full access to do whatever he wants in that directory when he logs in over the network, and I want nobody else to have any access (except maybe the Administrator).
I currently have it so jsmith can view the Folder, but he cannot create a subfolder in Staff/jsmith/. It tells him "Unable to create folder 'New Folder', Access is denied".

What I did is set it to share the jsmith folder and give user jsmith Full Control in the share permissions. I also changed the Security settings for the folder by taking the checkmark out of "Allow inheritable permissions from parent". Taking that out automatically deleted the "Everyone" above it, but I added John Smith, and Administrators. For some reason, even though I added jsmith to the security tab of the folder with full access, it doesn't work.
Any ideas?
 
It may be easier to just leave the share permissions at EVERYONE FULL CONTROL and work your permissions from the Security tab only. The more restrictive of the two will win. In other words, you can have EVERYONE FULL CONTROL on the share tab, but remove everyone from the security tab and then explicitly manage your permissions to certain users. Makes for much less confusion and gives the ability to set permissions at a much greater level.
 
Thanks Tekmazter, I did that and I have it working great now. The only thing I was concerned with is when other OS's logon that are not NTFS. I wanted them to be restricted by the security access also. I haven't tested logging in with win98 yet, so hopefully it works.

Thanks again.
 
An even easier way to solve the Staff folder issue is to open up the user properties in AD Users and Computers and go to the profile tab. Select a drive letter and have it mapp to \\servername\staff\username. That way no matter where they log in they have the same mapped drive and permissions in win 9X.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top