Help Me Understand File Permissions
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Help Me Understand File Permissions

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
ebferro
Guest





Posted: Wed Jan 12, 2005 6:39 pm    Post subject: Help Me Understand File Permissions Reply with quote

I have a file share that I've created on our cluster called ASuiteDB. I want
to allow users that belong the the group MDR2000 Group read/write/full
control permissions to that share. I don't want anyone else (except the AD
Administrators) to have access to that share. I created the MDR2000 Group
and assigned the group read/write/full control rights in the NTFS permissions
for the AsuiteDB file share. I deleted the Everyone group from the list of
those allowed permission to AsuiteDB. When I attempt to access the database
stored on AsuiteDB as a member of MDR2000 Group, I can read from the database
but am not allowed to write to it. If I add back the Everyone group and
assign it read/write/full control permissions, then things work fine. I
presume the MDR2000 Group is inheriting some permissions from the Everyone
group but don't know this for sure. How do I go about setting it up so that
members of the MDR2000 Group are the only ones allowed to read/write/full
control the AsuiteDB share (besides Administrators, of course). Thanks in
advance for the assistance.
Ernie
Back to top
Resonate
Guest





Posted: Wed Jan 12, 2005 9:21 pm    Post subject: Re: Help Me Understand File Permissions Reply with quote

From what you say it would seem the everyone group already exists further up
the tree.

Why is this? You may need to add MDR2000 as read and list (this folder
only) to the root folder above MDR2000

Res




"ebferro" <ebferro@discussions.microsoft.com> wrote in message
news:635ADBF2-317A-47BC-9000-53FDFA945010@microsoft.com...
Quote:
I have a file share that I've created on our cluster called ASuiteDB. I
want
to allow users that belong the the group MDR2000 Group read/write/full
control permissions to that share. I don't want anyone else (except the
AD
Administrators) to have access to that share. I created the MDR2000 Group
and assigned the group read/write/full control rights in the NTFS
permissions
for the AsuiteDB file share. I deleted the Everyone group from the list
of
those allowed permission to AsuiteDB. When I attempt to access the
database
stored on AsuiteDB as a member of MDR2000 Group, I can read from the
database
but am not allowed to write to it. If I add back the Everyone group and
assign it read/write/full control permissions, then things work fine. I
presume the MDR2000 Group is inheriting some permissions from the Everyone
group but don't know this for sure. How do I go about setting it up so
that
members of the MDR2000 Group are the only ones allowed to read/write/full
control the AsuiteDB share (besides Administrators, of course). Thanks in
advance for the assistance.
Ernie
Back to top
ebferro
Guest





Posted: Wed Jan 12, 2005 9:35 pm    Post subject: Re: Help Me Understand File Permissions Reply with quote

Res:
Thanks for taking the time to answer my query.
I'm not sure what you mean by 'further up the tree'. How can I view the tree?
Ernie

"Resonate" wrote:

Quote:
From what you say it would seem the everyone group already exists further up
the tree.

Why is this? You may need to add MDR2000 as read and list (this folder
only) to the root folder above MDR2000

Res




"ebferro" <ebferro@discussions.microsoft.com> wrote in message
news:635ADBF2-317A-47BC-9000-53FDFA945010@microsoft.com...
I have a file share that I've created on our cluster called ASuiteDB. I
want
to allow users that belong the the group MDR2000 Group read/write/full
control permissions to that share. I don't want anyone else (except the
AD
Administrators) to have access to that share. I created the MDR2000 Group
and assigned the group read/write/full control rights in the NTFS
permissions
for the AsuiteDB file share. I deleted the Everyone group from the list
of
those allowed permission to AsuiteDB. When I attempt to access the
database
stored on AsuiteDB as a member of MDR2000 Group, I can read from the
database
but am not allowed to write to it. If I add back the Everyone group and
assign it read/write/full control permissions, then things work fine. I
presume the MDR2000 Group is inheriting some permissions from the Everyone
group but don't know this for sure. How do I go about setting it up so
that
members of the MDR2000 Group are the only ones allowed to read/write/full
control the AsuiteDB share (besides Administrators, of course). Thanks in
advance for the assistance.
Ernie


Back to top
Lanwench [MVP - Exchange]
Guest





Posted: Thu Jan 13, 2005 12:59 am    Post subject: Re: Help Me Understand File Permissions Reply with quote

ebferro wrote:
Quote:
Res:
Thanks for taking the time to answer my query.
I'm not sure what you mean by 'further up the tree'. How can I view
the tree? Ernie

What Resonate means is, the permissions are being inherited from a
higher-level folder. You can change this - in the properties of the folder
in question, you can untick the option to inherit parent properties - and
choose "copy" when prompted, and then set the security as you wish on that
particular folder.

Quote:

"Resonate" wrote:

From what you say it would seem the everyone group already exists
further up the tree.

Why is this? You may need to add MDR2000 as read and list (this
folder only) to the root folder above MDR2000

Res




"ebferro" <ebferro@discussions.microsoft.com> wrote in message
news:635ADBF2-317A-47BC-9000-53FDFA945010@microsoft.com...
I have a file share that I've created on our cluster called
ASuiteDB. I want
to allow users that belong the the group MDR2000 Group
read/write/full control permissions to that share. I don't want
anyone else (except the AD
Administrators) to have access to that share. I created the
MDR2000 Group and assigned the group read/write/full control rights
in the NTFS permissions
for the AsuiteDB file share. I deleted the Everyone group from the
list of
those allowed permission to AsuiteDB. When I attempt to access the
database
stored on AsuiteDB as a member of MDR2000 Group, I can read from the
database
but am not allowed to write to it. If I add back the Everyone
group and assign it read/write/full control permissions, then
things work fine. I presume the MDR2000 Group is inheriting some
permissions from the Everyone group but don't know this for sure.
How do I go about setting it up so that
members of the MDR2000 Group are the only ones allowed to
read/write/full control the AsuiteDB share (besides Administrators,
of course). Thanks in advance for the assistance.
Ernie
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB