Jump to content

Recommended Posts

Posted

Hi All,

 

I've been asked to give a teacher access to the 'Admin' shared drive, but only to certain parts of it and not others...

 

There are one or two folders like Personnel and Confidential, that only SLT and some that only the SLT/Admin have access to.

 

So I was looking through how it had been shared and how access had been given or denied and it got me thinking - What is the easiest, clutter free, least convoluted, and scalable/adaptable way of doing it?

 

Security groups? If so, what is the best way to do it? Should I have a Security Group named after a shared drive ( say M:\ DRIVE) and include everyone I want to have access to that drive as a member of that group?

 

Or should I have Security Groups based on job title (say ADMIN) and then give that security group access to the drive and include the teacher in question as a member of that group? Then how do I exclude her from some folders? Turn off inheritable permissions and grant exclusive access to individuals?

 

Anyway, Tl;dr - Question in the title...

 

Is there a best practice way of doing this?

 

Kol.

Posted

We have:

 

Staff Shared - Access only to 'Staff' security group.

 

Admin Shared - Access to only 'Admin team' - Containing one folder called SLT which only 'SLT' has permission to view.

 

Student Shared - 'Students' have Read / Write but not delete. 'Staff' have full perms.

Posted
We use security groups per department. Each department has a folder on a common area and within each folder there is a public folder (read everyone, write dept) for sharing resources and a departmental folder (read/write department only)
Posted

At the Academy I work at, the drives are mapped via GPO, Staff Shared, Pupil Shared. Inside the Staff Drive there are folders for departments e.g. Admin, SLT etc. We use security permissions in order to lock them down so to speak. Our security permissions go on departments, so all admin staff would be part of admin, SLT would be part of SLT group. and then we simply add the security group that needs access to that specific folder, you may find that more than one security group needs access to one folder. we also disable inherit permissions.

 

Hope this helps.

Posted
I inherited a system that works well, its a KIX logon script that maps drives based on what security groups members are in,e.g. I can quickly give access to a folder for a user just by adding them to the appropriate security group
Posted

Security Groups are the way to go, but if you need to add just the one user, then you can of course add them manually as a one off. If more need it, then I would create another Security Group.

 

You obviously can't apply this on the root of the share, so the only way is to ask SLT to split the data accordingly into two folders, then give the teacher in question access to the branch they require only, then enforce inheritance.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...