Jump to content

Recommended Posts

Posted

For some reason I'm really struggling with permissions today. I could use a second set of eyes.

 

I've created a new drive that is mapped via group policy. Teaching staff will have write access, pupils will have read access. I've been reading about share vs NTFS permissions and the best practice seems to be to give authenticated users full control on the share permissions and do the actual restrictions on the NTFS permissions, because between the two the most restrictive permissions always gets applied. So that's what I've done, and on the NTFS permissions I've assigned the pupils group read only access.

 

However, when I log on with a test pupil account, I can create files and folders on the drive.

 

NTFS permissions:

NTFS permissions.PNG

 

Effective access:

effective access.PNG

 

As you can see from the effective access tool, the test pupil account has the read permissions but also 'create files/folders'...from somewhere.

 

Has anyone got any ideas?

Posted
at a guess you have inherited permissions that allow users that you dont want permissions to have them (i cant remember which group it is from memory as i alter the default permissions pretty much when i format the drive as it takes less time with 0 data on it)
  • Thanks 1
Posted
As others have said, you will probably be inheriting "Everyone - Create" from the root of the drive, take that one out and it should work as expected.
  • Thanks 1
Posted
On the folder Go down to Properties, Click on Security and then go to advanced, This should tell you where the permissions are inherited from.

As far as I can tell it's not being inherited from anywhere.

 

Inherited.PNG

Posted
if i had to guess id say the 2nd from bottom permission is the culprate id check what permissions "special" are and id lay odds its modify/create
  • Thanks 1
Posted
I thought that too, but doesn't 'Users' mean local users on the file server? Of which there aren't any? The pupils are obviously all domain users.

youd think so but iirc it dosent work as you think it should

Posted
I thought that too, but doesn't 'Users' mean local users on the file server? Of which there aren't any? The pupils are obviously all domain users.

 

On any domain joined machine, "Domain Users" is a member of the local "Users" group (in the same way that "Domain Admins" is a member of the local "Administrators" group)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...