Jump to content

Recommended Posts

Posted

Hi

im running server 2008 at our school. It's the main DC. in the sysvol folder i have a folder which has shortcuts that are placed on the desktops. Recently 2 folders have been created which are named as 2 users on the domain. The problem is everyone now sees these folders on the desktop. Logged in as administrator on the server I can access the following folder:

 

\\SERVER\sysvol\alhijrah.pri\Policies\curriculum\Desktop\Folders named as users

 

When trying to delete the folders named as a user on the domain it says access denied

 

error code 0x80070005 Access denied.

 

Ive checked all the permissions for Domain Admin and they are all fine. Really need to get these removed

 

Any advice is much appreciated.

Posted

Is there a reason you're using sysvol rather than a shared user drive for this?

 

You could reset permissions on the top folder, and make sure they cascade down, but the idea of deleting things from SYSVOL is more than a little scary. Might be worth looking into creating a shared user drive instead, and pushing that out when people log on.

Posted
Is there a reason you're using sysvol rather than a shared user drive for this?

 

You could reset permissions on the top folder, and make sure they cascade down, but the idea of deleting things from SYSVOL is more than a little scary. Might be worth looking into creating a shared user drive instead, and pushing that out when people log on.

 

All this was already set before i came into the post so i dont want make any drastic changes if its already working. I will check that the permissions are cascading, which im sure they are. What i'd like to know is how did they get there in the first place. My inclination would be that these users who are MIS users thus are local admins also on their machines have access to their desktops. Maybe policy is bot applied correctly.

 

Let's see how we get on.

Posted
Just a word of warning: I made some changes to permissions on SYSVOL on a test network and locked out administrator and all other users from the test network [At the time we had XP and I was trying to stop students navigating their way through the folder structure from the Start Menu]
Posted

Take ownership of the folders by logging onto one of your DCs as a domain admin, or administrator and right click->properties->Security->Advanced->Ownership and ensure you set yourself as owner and propogate the permissions down.

 

Seems a strange place to put custom folders tbh...

Posted
As the others have said, it would be best (scrub that, it WILL be best) if you put the shortcuts etc in a regular network share. Sysvol can be a bit like the defualt domain policy in AD. Not something you want to be messing around with at times, especially when it comes to permissions.
Posted
As the others have said, it would be best (scrub that, it WILL be best) if you put the shortcuts etc in a regular network share. Sysvol can be a bit like the defualt domain policy in AD. Not something you want to be messing around with at times, especially when it comes to permissions.

 

Thanks. I agree with you all about placing shortcuts on the share. But doing this mid term will cause alot of problems with staff and pupils. More so with staff as they refuse to listen lol

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...