reggiep Posted November 20, 2013 Posted November 20, 2013 We currently have a shared folder called staff that all the staff have access to. Within that are folders such as Admin, pupil premium, geog, humanities etc. This morning somebody noticed that the pupil premium folder had been deleted by presons unknow. I restored it with shadow copy from yesterday lunch which nice. However I have now been asked to lock it down so staff can't delete folders! I could set permissions on all these folders so that staff can't delete them but then they might delete subfolders. DO I then set it so they can't delete sub folders. Of course there are the files themselves. Do I do the same on that so that staff cannot delete anything at all in those folders? How much of a burden does this then create for staff to have to contact me to request a file to be deleted? Anyone any thoughts on this?
Andrew_C Posted November 20, 2013 Posted November 20, 2013 You sure it was deleted? What ours have done in the past is a sort of "Clickkkdraaaggg" and drop it in another folder. Can't be found unless you can search for something in it.
reggiep Posted November 20, 2013 Author Posted November 20, 2013 Good thought! But still I have been tasked with this now!
fiza Posted November 20, 2013 Posted November 20, 2013 Wont the shared folder get clogged up with rubbish because users cant delete anything? Give majority of staff read access to the important stuff and read/write to those who need it or you could lock it down so only "owner" could delete?
reggiep Posted November 20, 2013 Author Posted November 20, 2013 Wont the shared folder get clogged up with rubbish because users cant delete anything? Give majority of staff read access to the important stuff and read/write to those who need it or you could lock it down so only "owner" could delete? I like the owner idea, I was just looking into that now!
bushby Posted November 20, 2013 Posted November 20, 2013 im in the same thing at the moment, what im doing is the root of the staff shares are locked down so that only the ict team can make the folders then with in them the sub-folders are then managed by the retentive personal.
reggiep Posted November 20, 2013 Author Posted November 20, 2013 retentive personal. I like the sound of those staff!
zag Posted November 20, 2013 Posted November 20, 2013 We make the root read only and all the folders inside writeable. Most of the time its staff clicking and dragging folders, and this method prevents that in most cases This also protects from viruses that copy themselves to shared drives such as conflicker.
Ephelyon Posted November 20, 2013 Posted November 20, 2013 Keep the permissions the same, but enable shadow copies and access auditing for delete operations on that folder?
mjs_mjs Posted November 20, 2013 Posted November 20, 2013 what im doing is the root of the staff shares are locked down so that only the ict team can make the folders then with in them the sub-folders are then managed by the retentive personal. I did this 4-6 years ago going from RM cc3-cc4. I used DFS, and had the staff shared, student shared and the archives appear all on 'one' drive for users. It got alot of questions but soon people realised that it was quite a good idea. Everything in one place, but with super restrictive ntfs and individual share permissions. Top level was DFS, next level was folders I set, and only IT tech could change/add/modify, within that there were departmental folders with restricted permissions to staff/students and the archive was read only for staff. Devil is in the detail - just make sure you enforce a strict principle of least access. Shadow copies were also enabled but only for IT tech's.
xenonive Posted November 20, 2013 Posted November 20, 2013 I agree about setting the permissions correctly.We just enable shadow copies twice a day on the share then if something is deleted we can restore it back to date it was there.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now