View Full Version : Restriction Hell!! (W2K)
mattonarock
05-26-2004, 12:58 AM
This has been buggng me for the past couple of days. Basically I want to be able to restrist an area on my network so that users can read/write files but I don't want them to create folders and delete. This sounds simple and under NT4 / Novell it was just a case of giving them read/write/list acccess. However things seem to have gotten a little more complicated with Win2000/AD. The create folder/append data permission seems to be tied in with write data so it seems to be that you can't take away the ability to create folders without taking the save ability away as well.
Has anyone got an suggestions on how to fix this?
<P ID="edit"><FONT class="small">Edited by mattonarock on 05/26/04 00:04.</FONT></P>
SystemEngineer
05-27-2004, 09:27 AM
On the security tab of a folder click the advanced tab, you can deny users creating folders etc but allow them to create files and folders in the sub directories. Although it may seem a jump from NT and Novell, once you have learnt to administer 2K - beyond you won't look back.
If you're still having difficulties with this let me know and i'll give a step by step walkthrough.
Kind Regards.
mattonarock
05-28-2004, 12:36 AM
Thanks SystemEngineer, I have tried this but I am still having problems. Would you be so kind as to do a quick run thorugh of what needs to be done, if you want you can email me matt@su****ech.com which would be very helpful. Thanks very much.
SystemEngineer
05-28-2004, 01:44 AM
Ok first things first create a folder, right click the folder, you should see that there are already some users and groups assigned permissions to that folder. Click the Advanced tab, uncheck the box 'Allow inheritable permissions...', now a dialog may appear giving you the options to copy or remove permissions. Select copy. Now remove the groups and users that don't need to be there, but make sure the important groups and users are there, i.e. Administrators, you and System. Now let’s say you want to give John read\write access to the folder but don't want him to delete the folder.
Now leave the advanced tab and return to the standard security tab. Add your user 'John' and give him permission to modify. Now select the advanced tab, and click 'Add' and add user 'John' again, you should now see a list of options, at the top there is a drop down box saying 'Apply Onto:' Select 'This folder only', and deny him from deleting the folder (not subfolders). Now Add user 'John' again, and on the drop down box select 'subfolders only' and deny him from creating them.
User John should now be able to create and modify files within the folder, but not delete the folder or create folders inside the folder.
I hope this is not too complicated. But any other questions don't hesitate to ask.
Kind Regards.
mattonarock
05-28-2004, 02:35 AM
Thanks mate, really appreciate your help :)
Just one other thing, it's all worked except users can still delete files.
<P ID="edit"><FONT class="small">Edited by mattonarock on 05/28/04 01:47.</FONT></P>
SystemEngineer
06-02-2004, 07:21 AM
Sorry for the delayed reply. If you want to stop them from deleting the files in the folder but allow them to create and edit the files, on the advanced tab of the security dialog add the user or group you want to deny, make sure it applies only to the files within that folder and then deny them deleting files.
Hope this helps.
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.