Jump to content

Recommended Posts

Posted (edited)

I finally tracked down an issue I've had with office for over a decade. Where upon selecting "documents" to save a restricted message would appear, then pressing "ok" would open "documents" just fine..

 

Well it must be an oddity with my GPOs or the user share is made or something else... I've found that office whilst the default save location is "documents" the autorecover documents are in "appdata" (in the office settings). Now that I've lifted restrictions on my test pupil, clicking "documents" as a save location in office wants to save the document into appdata!?!

 

I think this is because the pupil does NOT have "grant exclusive permissions" enabled on their user area. ("documents" fails to redirect if I enable that option)

 

Do you have exclusive permissions for pupil areas? How do I configure the share to allow this? (as GPO fails to apply it if set in the redirect GPO)

 

The full save location is the network shortcut folder which maybe important!

Edited by chazzy2501
important point missed!
Posted
I finally tracked down an issue I've had with office for over a decade. Where upon selecting "documents" to save a restricted message would appear, then pressing "ok" would open "documents" just fine..

 

Well it must be an oddity with my GPOs or the user share is made or something else... I've found that office whilst the default save location is "documents" the autorecover documents are in "appdata" (in the office settings). Now that I've lifted restrictions on my test pupil, clicking "documents" as a save location in office wants to save the document into appdata!?!

 

I think this is because the pupil does NOT have "grant exclusive permissions" enabled on their user area. ("documents" fails to redirect if I enable that option)

 

Do you have exclusive permissions for pupil areas? How do I configure the share to allow this? (as GPO fails to apply it if set in the redirect GPO)

 

The full save location is the network shortcut folder which maybe important!

 

Exclusive rights should not prevent anything working as far as I know. We used to redirect at a previous place and always un-cheched the box. We had a redirected desktop for students which they had only read access too which was also quite handy. 1 it stopped the saving to the desktop, 2 we were able to put links on the desktop.

Posted

ok, this is an issue I ADOPTED! This has been wrong for 20+ years!

 

The way the root share folder was setup for the users didn't have the correct ntfs permissions. I had to add an "authenticated users" with read permissions to the root folder and full control over the share.

 

it's always worked so I've never checked or had reason to make one from scratch.. (until today) lol!

Posted (edited)

dang, easy for a new folder but I can't retrospectively add this security permission... I get access denied, I can't take ownwership of 800+ accounts to add it without some disruption!

 

EDIT: I added the permissions to a parent folder and I "think" it is propagating down as inheritance appears to be on. No idea how to check.

Edited by chazzy2501
Posted
final point, I only needed to add read permissions "authenticated users" to the parent folder (the one with the share) "this folder only" it doesn't need to be inherited. This also fixed a long standing issue with Affinity Photo 2 with exports.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...