Koldov Posted January 22, 2015 Posted January 22, 2015 Hi All, I've been asked to give a teacher access to the 'Admin' shared drive, but only to certain parts of it and not others... There are one or two folders like Personnel and Confidential, that only SLT and some that only the SLT/Admin have access to. So I was looking through how it had been shared and how access had been given or denied and it got me thinking - What is the easiest, clutter free, least convoluted, and scalable/adaptable way of doing it? Security groups? If so, what is the best way to do it? Should I have a Security Group named after a shared drive ( say M:\ DRIVE) and include everyone I want to have access to that drive as a member of that group? Or should I have Security Groups based on job title (say ADMIN) and then give that security group access to the drive and include the teacher in question as a member of that group? Then how do I exclude her from some folders? Turn off inheritable permissions and grant exclusive access to individuals? Anyway, Tl;dr - Question in the title... Is there a best practice way of doing this? Kol.
fairm010 Posted January 22, 2015 Posted January 22, 2015 We have: Staff Shared - Access only to 'Staff' security group. Admin Shared - Access to only 'Admin team' - Containing one folder called SLT which only 'SLT' has permission to view. Student Shared - 'Students' have Read / Write but not delete. 'Staff' have full perms.
ChrisH Posted January 22, 2015 Posted January 22, 2015 We use security groups per department. Each department has a folder on a common area and within each folder there is a public folder (read everyone, write dept) for sharing resources and a departmental folder (read/write department only)
DavetheITguy Posted January 26, 2015 Posted January 26, 2015 At the Academy I work at, the drives are mapped via GPO, Staff Shared, Pupil Shared. Inside the Staff Drive there are folders for departments e.g. Admin, SLT etc. We use security permissions in order to lock them down so to speak. Our security permissions go on departments, so all admin staff would be part of admin, SLT would be part of SLT group. and then we simply add the security group that needs access to that specific folder, you may find that more than one security group needs access to one folder. we also disable inherit permissions. Hope this helps.
caffrey Posted January 26, 2015 Posted January 26, 2015 I inherited a system that works well, its a KIX logon script that maps drives based on what security groups members are in,e.g. I can quickly give access to a folder for a user just by adding them to the appropriate security group
Michael Posted January 26, 2015 Posted January 26, 2015 Security Groups are the way to go, but if you need to add just the one user, then you can of course add them manually as a one off. If more need it, then I would create another Security Group. You obviously can't apply this on the root of the share, so the only way is to ask SLT to split the data accordingly into two folders, then give the teacher in question access to the branch they require only, then enforce inheritance.
MrFrostmaul Posted January 26, 2015 Posted January 26, 2015 We map all ours via Group Policy mapping and it based on OU group, for a subject share we have all staff are mapped to it, but only depts can access their subject folder.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now