Jump to content

Recommended Posts

Posted

Hey Guys

 

Hoping one of you geniuses can give me a hand here! We have an admin folder where all the admin stuff such as attendance etc.. is. It sits on the staff share so everyone has been able to see it and open the documents inside which the head teacher flipped about and wants only the admin staff to be able to access it.

 

Easy enough I thought I will simply add all the admin staff into a AD Security Group and delete all the other Users/Groups who have access to the folder in security I will then give this Group Full Control and none else including the Administrator Username.

 

It hasn't worked like that none can access anything and the files and sub folders can't even be accessed by me the administrator! I'm really worried now as I have just checked and our FRIGGING BACKUP has failed! I'm loosing the will to live someone please help!

 

:(

Posted

ok, you should be able to take ownership of the folder, using the instructions in the link below, to get the administrator account its access back, then try the security policies again.

 

Take Ownership of a File or Folder

 

I have done this before, it is worrying, but it is all still there, you will be fine :-)

Posted

You may need to take ownership of the folder plus subfolders/files and then re-do the permissions(security>advanced>ownership). Did you enter any deny permissions entries? these override any grant's that are in place.

 

Also in general I'd always leave the domain admins group with read permissions at the very least to allow backups to be performed

Posted
Ok I've took ownership of the folder and some files seem to open the others say they're corrupt and cannot be opened. The flaming backup hasn't backed up that one particular folder for some odd reason and I can't get it back.
Posted
Yep still not working, a select few of the folders have padlocks next to them and when I try to open a word document or PDF inside of them it says I do not have the rights to access the files!? GAHHH
Posted

Did you tell it to propagate the child folders with the new ownership / access permissions when you took ownership as it just sounds like it's not been through the process of updating the child folders of that top level admin folder.

 

Also, when you were locking it down, how did you go about that? The one rule to remember (that I learned in a very similar way to how you sound to be now) is don't check deny on the upper-most level that a staff member might have (so if the admins are a member of users, staff and schooladmins, if you check to Deny access on staff or users, this will also apply to the schoolsadmins group). Only use Deny to explicitly make sure a particular group (say students) can't access the folder. If you don't want staff to access it, just remove all the groups other than the one you do want to access it, then Windows normally will behave.

 

As others have mentioned though, may sure you leave at least some admin read access for backups and such.

 

Hope you get it sorted.

Posted
It seems that some folders and files within the admin area aren't updating their permissions, there are far too many files to edit the permissions one by one can someone please help me I'm really stressed out should have left work over an hour ago now!
Posted

EDIT: Didn't see the new posts! :)

 

Try opening a command prompt and navigating to the folder above this admin one, then running this:

 

takeown /a /r /f FolderName

 

See what messages you get. I'm around for another half hour or so.

Posted

If you right click on the main folder, and click properties, then click on the security tab and click Advanced.

 

On the Owner Tab of the advance, click Edit and choose the admin group / your account (which ever it is your trying to get back control to). The ones you can choose should be listed in the box.

 

Underneath that, there is a box "Replace Owner on subcontainers and objects" - make sure this is checked then click ok.

 

This will then go through the process of updating the owner on all the contents of that folder.

 

Once done, you can then in the advanced settings go into the Permissions Tab and click on "Change Permissions" which will bring up a page for you to set permissions on.

 

If you're doing custom permissions and this folder is within an existing structure staff have access to, then uncheck the "include permissions from this object's parent" box and also make sure you check the "Replace all child object permissions with inheritable permissions from this object" and then set the permissions for people you want to access the folder.

 

Personall, I would remove all the ones there, add the standard administrators group to it with full control (assuming staff aren't admins) and then add the group for the admin staff on there with full control, this should then mean anyone outside of those 2 groups cannot access this folder. You could of course limit either of those groups to only have specific controls, but to get it working, the above should be fine.

 

Click ok and it should go through the process of updating all the child object permissions and such (you'll probably get an Are You Sure box).

 

Then, log on as a member of staff to make sure they can't access it, if they can't, brilliant, then log on as a member of admin staff (set up test accounts if no one is about to do this for you if you don't have them already) and if they can access it, job done, go home, and take some EduHobNobs and Whiskey with you! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...