Permission question

A

Adam Raff

Good day,

I have a server that the permissions have been setup. The folders have been
setup by department and the department it question is the Art department

Now I need to change the folded rights on a folder and it's sub folders to
allow all users access the account so that everyone can open and read the
files.

Currently I have set up the folders by department and the art department has
modify rights to do what they want on this folder. Thus they can create new
folders and so forth. The folder in question is called "Art folder" and
the parent folder is called "Artcomm" and what I am doing is sharing the Art
folder out so that everybody can access the folder and I will give the
folder a drive letter that will allow easy access for all users.

My problem now is rights since the Art department has modify rights and the
art department users are part of the everyone group and I give the everyone
group only read & execute rights and list folder contents and read will that
over right the art departments rights so they can only do what the everyone
group can do. Which is not good. If this is the case how can I set this up
so that the Art department and other group still has rights that they need
and yet the rest of the users have the minimum rights to open and view the
files.

I understand that I will have to go into advanced and uncheck inheritable
permissions and then check replace permission entries on all child objects.
Since I need to get these new rights down to the subfolders and not inherit
the rights of the parent which is Artcomm.

Thanks for your help in this matter
Adam Raff
 
A

Adam Raff

One more thing that I would like to add. I have divided my users also into
groups by department if that helps.

Thanks Again
Adam Raff
 
P

Pegasus \(MVP\)

Adam Raff said:
Good day,

I have a server that the permissions have been setup. The folders have been
setup by department and the department it question is the Art department

Now I need to change the folded rights on a folder and it's sub folders to
allow all users access the account so that everyone can open and read the
files.

Currently I have set up the folders by department and the art department has
modify rights to do what they want on this folder. Thus they can create new
folders and so forth. The folder in question is called "Art folder" and
the parent folder is called "Artcomm" and what I am doing is sharing the Art
folder out so that everybody can access the folder and I will give the
folder a drive letter that will allow easy access for all users.

My problem now is rights since the Art department has modify rights and the
art department users are part of the everyone group and I give the everyone
group only read & execute rights and list folder contents and read will that
over right the art departments rights so they can only do what the everyone
group can do. Which is not good. If this is the case how can I set this up
so that the Art department and other group still has rights that they need
and yet the rest of the users have the minimum rights to open and view the
files.

I understand that I will have to go into advanced and uncheck inheritable
permissions and then check replace permission entries on all child objects.
Since I need to get these new rights down to the subfolders and not inherit
the rights of the parent which is Artcomm.

Thanks for your help in this matter
Adam Raff

Do this:
- Give the "Everyone" group "read & execute" rights.
- Give the "Art" group "Modify" rights.

You will find that the "Art" group will NOT be restricted to the
rights granted to the "Everyone" group, even though members
of the "Art" group are also members of the "Everyone" group.
 
K

Ken Zhao [MSFT]

Hello Adam,

Thank you for using newsgroup!

From your post, I agree with our MVP Pegasus's suggestions. For more
related information, please refer to the following articles:

Where Access Control Information Comes From
<http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit
/en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/e
n-us/distrib/dsce_ctl_ataf.asp>

File and Folder Permissions in Windows 2000
<http://www.microsoft.com/technet/prodtechnol/windows2000serv/deploy/confeat
/13w2kadc.mspx>

Hope that helps!

Thanks & Regards,

Ken Zhao

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.




--------------------
| From: "Pegasus \(MVP\)" <[email protected]>
| References: <#[email protected]>
| Subject: Re: Permission question
| Date: Tue, 29 Nov 2005 10:34:00 +1100
| Lines: 56
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Outlook Express 6.00.2800.1506
| X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1506
| Message-ID: <[email protected]>
| Newsgroups: microsoft.public.win2000.general
| NNTP-Posting-Host: 220-253-28-156.vic.netspace.net.au 220.253.28.156
| Path: TK2MSFTNGXA02.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
| Xref: TK2MSFTNGXA02.phx.gbl microsoft.public.win2000.general:193994
| X-Tomcat-NG: microsoft.public.win2000.general
|
|
| | > Good day,
| >
| > I have a server that the permissions have been setup. The folders have
| been
| > setup by department and the department it question is the Art department
| >
| > Now I need to change the folded rights on a folder and it's sub folders
to
| > allow all users access the account so that everyone can open and read
the
| > files.
| >
| > Currently I have set up the folders by department and the art department
| has
| > modify rights to do what they want on this folder. Thus they can create
| new
| > folders and so forth. The folder in question is called "Art folder"
and
| > the parent folder is called "Artcomm" and what I am doing is sharing the
| Art
| > folder out so that everybody can access the folder and I will give the
| > folder a drive letter that will allow easy access for all users.
| >
| > My problem now is rights since the Art department has modify rights and
| the
| > art department users are part of the everyone group and I give the
| everyone
| > group only read & execute rights and list folder contents and read will
| that
| > over right the art departments rights so they can only do what the
| everyone
| > group can do. Which is not good. If this is the case how can I set
this
| up
| > so that the Art department and other group still has rights that they
need
| > and yet the rest of the users have the minimum rights to open and view
the
| > files.
| >
| > I understand that I will have to go into advanced and uncheck
inheritable
| > permissions and then check replace permission entries on all child
| objects.
| > Since I need to get these new rights down to the subfolders and not
| inherit
| > the rights of the parent which is Artcomm.
| >
| > Thanks for your help in this matter
| > Adam Raff
|
| Do this:
| - Give the "Everyone" group "read & execute" rights.
| - Give the "Art" group "Modify" rights.
|
| You will find that the "Art" group will NOT be restricted to the
| rights granted to the "Everyone" group, even though members
| of the "Art" group are also members of the "Everyone" group.
|
|
|
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top