Windows Server - allow write to child folder, deny write to parent
Asked By techstress
27-Jan-10 09:13 PM
is it possible to deny access to create files on the root of a drive
and still allow modify access to subfolders?
Desk
(1)
OThe
(1)
Hides
(1)
Hers
(1)
ADUC
(1)
Dusko Savatovic replied to techstress
Yes, no problem.
On the child folder, uncheck "Include inheritable permissions from this
object's parent" and adjust permissions as you like.
techstress replied to Dusko Savatovic
The problem I am encountering is that we have a drive for user home
folders. However, some users are saving files to the root of the
drive. I'd like to deny access to any file saved to the root of the
drive, yet still allow the users to create & modify files to their
home folders.
I think the fix Dusko suggested would allow the user to set custom
permissions on their home folder.
Matija Kapraljevic [Revenger] replied to techstress
I think Dusko is right on the spot with this.
Have you tried what he suggested?
Also, do your users have admin rights? If not (and you do), then you can
set up security permissions for the folders and they should not be able to
change them ...
techstress replied to Matija Kapraljevic [Revenger]
o
The users do not have admin rights to the file server.
I think I would need to remove create files permission to the root of
the drive. this would not allow the users to create files on the root
of the drive.
Then, I can try customizing security on their home folder to allow
full control. This should allow full access to the user's home
folders.
Matija Kapraljevic [Revenger] replied to techstress
Yes, that should do it ... but, are you even trying to configure this or
are you just thinking about doing it?
Go ahead, make one 'dummy' user, set just his/hers permissions in the root
folder to deny Write and/or Modify rights, and then set whatever
permissions you like on the users home (sub)folder. Make sure you uncheck
'Inherit permissions from parent ...' like Dusko said you should.
Log in with that user and give it a try ... you cannot mess things up if you
set it up for just that user.
When you have tested it, and you are satisfied with the result, make the
changes for all other users and delete the 'dummy' user.
Then come back here and give us some feedback. If you need some more help,
we will try to help you, if not, we will know its working and other people can
use the same solution if they encounter a similar problem.
DaveMills replied to techstress

Everything said by others on this thread is true but it is easier than that.
1) Create the folder for holding home folders. Lets call it "Home"
2) Set the permissions on this folder to allow those that should be able to see
all home folders. For example Administrators = F/C and "Help Desk" = Modify (or
read as you need). Do not add "Users", "everyone" etc.
3) Use ADUC to set a users home folder, e.g. map H: to \\server\Home$\%username%
ADUC will create the home folder and give the user F/C permissions. The
permissions in step 2) will inherit to the new home folder. The user will be
able to do everything to their own folder.
If the open \\server\home$ they will be able to do anything to their own home
folder but not to other user's home folders no create new files/folders in
Home$.
It you enable Access Based Enumeration then they will not even see any content
in \\server\home$ except their own home folder.
As an alternative you could change the permissions for the user from F/C to
Modify and they will no longer be able to alter the folder permissions. You
cannot stop them changing permissions on files/folders they create in their home
folder as they will be owners.
Normally they will use the mapped drive to access their home folder so will
never see \\server\home$. Having a $ on the share name hides it from the browser
so they will not easily stumble upon it either. It is visible as a path in the
My Computer listing of the mapped drive though so this is a feature to stop idle
browsing not a security feature.
--
Dave Mills
There are 10 types of people, those that understand binary and those that do not.

it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) Also, they had me download something and save it on my desk top, But for this I 'm not clear what it does, so I had to it is but anyway) | Also, they had me download something and save it on my desk top, | But for this I 'm not clear what it does, | so I had to
ADUC: cannot export advanced query results Windows Server Hi, from ADUC I can export displayed lists including those from "saved queries". However, if I use "find XP (1) CSci (1) QueryThere (1) Directory (1) Achiever (1) Month (1) I am running ADUC from rsat in Win7 and it is available to me. I wonder if older versions This posting is provided "AS IS" with no warranties and confers no rights. I ran ADUC on Windows 2003 and XP for a Windows 2003 domain (Mixed mode). What's the version of ADUC on Windows 7? I wonder whether the version of the ADUC or the Domain (forest) functiona level matters. Can't seem to locate the version but 2010 05:48 ET : query There is no option available to export query results in ADUC older versions. You can create a new saved query (all advanced query features are available then export the required results to a txt file. its simple as that. . . Thanks keywords: ADUC:, cannot, export, advanced, query, results description: Hi, from ADUC I can export displayed lists including
Is there a Help Desk in SBS2K8 Windows Server Is there a Help Desk in SBS2K8 in Sharepoint? Windows Server SBS Discussions SharePoint (1) Companyweb (1) Desk (1) SBS (1) No, there is not a built-in Help Desk in the SBS 2008 SharePoint. If you are migrating from SBS 2003, it should be possible to migrate your existing help desk to the new Companyweb site. And there is a Help Desk template for SharePoint 3.0 that is available for download. (http: / / www.microsoft.com / downloads Charlie. http: / / msmvps.com / blogs / russel Thanks for the info. keywords: Is, there, a, Help, Desk, in, SBS2K8 description: Is there a Help Desk in SBS2K8 in Sharepoint?
can not remote desk windows 2003 server on winxp, win 7, but it is OK on win 2008 Windows of windows 2003 servers through ghost image. But I find that I can not remote desk the servers on winxp, win 7, the event log of win 2003 is below: Event fwlink / events.asp. but it is successful when I login win 2008 and then remote desk the server2003 with same account. thanks, Windows Terminal Services Discussions Windows XP (1) Error (1 after I add the servers into the domain, I can login the servers with remote desk. 2. I can not login the servers on win XP or win 7 with the login the servers. But I do not know why? Thanks, Tiger keywords: can, not, remote, desk, windows, 2003, server, on, winxp, , win, 7, , but, it, is, OK, on, win, 2008 description of windows 2003 servers through ghost image. But I find that I can not remote desk the servers on winxp, win 7, the event log of w
script and find that their password has not changed for over 90 days. However, Help Desk can not run the script to see this date. (obviously Help desk would not run a script.) Is their any way to view Password Last Changes or Address, Profile. . .etc. . We have 2003 AD Native Windows Server Active Directory Discussions Proerties (1) Desk (1) Pwdlastset (1) Attributes (1) Windows (1) Poboy (1) Hello poboy_n.o_style, Install and use Users OU and find the user but it does not show up when the Help desk does a FIND Users. keywords: pwdlastset, View, in, AD description: We changed our passwords every