Jump to content

Recommended Posts

Posted

This has hapenned to 3 users in past 3 weeks (2 Students, 1 Staff), we have approx 10,000 users altogether.

 

The folders randomly get a Deny Permission on the home folder even though the folders have data that has been written to by the user.

 

We have separate servers for Staff and Students both running Server 2008 R2.

 

Just seems a bit strange and wondered if anyone else getting similar issues. We run Sophos Endpoint Anti-Virus but nothing showing in logs.

 

Big team here so hoping it is just someone not knowing what they are doing.

Posted
We had similar issue few times, I didn't get a chance to troubleshoot it properly so I don't know what is causing it all I know is that deleting/renaming roaming profile fixes it in our case.
  • Thanks 1
Posted

Try running a command like this across all your users on your 2008 R2 Server:

 

@echo off
icacls "d:\users\username1\*" /q /c /t /reset
icacls "d:\users\username2\*" /q /c /t /reset
icacls "d:\users\username3\*" /q /c /t /reset

 

This resets the permissions on the root of every home folder, re-adds their permissions, but also applies this to all sub folders and files.

  • Thanks 1
Posted
We had similar issue few times, I didn't get a chance to troubleshoot it properly so I don't know what is causing it all I know is that deleting/renaming roaming profile fixes it in our case.

 

Thanks, We don't use Roaming profiles at all here, haven't used them for years :D

 

Try running a command like this across all your users on your 2008 R2 Server:

 

@echo off
icacls "d:\users\username1\*" /q /c /t /reset
icacls "d:\users\username2\*" /q /c /t /reset
icacls "d:\users\username3\*" /q /c /t /reset

 

This resets the permissions on the root of every home folder, re-adds their permissions, but also applies this to all sub folders and files.

 

Thanks Michael, Got a similar type of script which resets permissions and changes ownership which I'll probably run over weekend.

Posted
We have had this on several occasions and fixed it with logging off and on again to deleting profiles. We have noticed this sort of issue happens far more than it used to.
Posted

Try running this powershell script...usually corrects any issues with permissions.

 

 

#            Variables
#Put quotes around homedrives directory and domain name. This will be your UNC path
# Where is the root of the home drives?
$homeDrivesDir=
# Report only? ($false = fix problems)
$reportMode = $false
# Print all valid directories?
$verbose = $false
# What domain are your users in?
$domainName = 
# ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?

# Save the current working directory before we change it (purely for convenience)
pushd .
# Change to the location of the home drives
set-location $homeDrivesDir

# Warn the user if we will be fixing or just reporting on problems
write-host ""

if ($reportMode) {
Write-Host "Report mode is on. Not fixing problems"
} else {
Write-Host "Report mode is off. Will fix problems"
}

write-host ""

# Initialise a few counter variables. Only useful for multiple executions from the same session
$goodPermissions = $unfixablePermissions = $fixedPermissions = $badPermissions = 0
$failedFolders = @()

# For every folder in the $homeDrivesDir folder
foreach($homeFolder in (Get-ChildItem $homeDrivesDir | Where {$_.psIsContainer -eq $true})) {

# dump the current ACL in a variable
$Acl = Get-Acl $homeFolder

# create a permission mask in the form of DOMAIN\Username where Username=foldername
#    (adjust as necessary if your home folders are not exactly your usernames)
$compareString = "*" + $domainName + "\" + $homeFolder.Name + " Allow  FullControl*"

# if the permission mask is in the ACL
if ($Acl.AccessToString -like $compareString) {

# everything's good, increment the counter and move on.
if ($verbose) {Write-Host "Permissions are valid for" $homeFolder.Name -backgroundcolor green -foregroundcolor white}
$goodPermissions += 1

} else {
# Permissions are invalid, either fix or report
# increment the number of permissions needing repair
$badPermissions += 1
# if we're in report mode
if ($reportMode -eq $true) {
# reportmode is on, don't do anything
Write-Host "Permissions not valid for" $homeFolder.Name -backgroundcolor red -foregroundcolor white
} else {
# reportmode is off, fix the permissions
Write-Host "Setting permissions for" $homeFolder.Name -foregroundcolor white -backgroundcolor red
# Add the user in format DOMAIN\Username
$username = $domainName + "\" + $homeFolder.Name
# Grant the user full control
$accessLevel = "FullControl"
# Should permissions be inherited from above?
$inheritanceFlags = "ContainerInherit, ObjectInherit"
# Should permissions propagate to below?
$propagationFlags = "None"
# Is this an Allow/Deny entry?
$accessControlType = "Allow"
try {
# Create the Access Rule
$accessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($username,$accessLevel,$inheritanceFlags,$propagationFlags,$accessControlType)

# Attempt to apply the access rule to the ACL
$Acl.SetAccessRule($accessRule)
Set-Acl $homeFolder $Acl
# if it hasn't errored out by now, increment the counter
$fixedPermissions += 1
} catch {
# It failed!
# Increment the fail count
$unfixablePermissions += 1
# and add the folder to the list of failed folders
$failedFolders += $homeFolder
}
} #/if
} #/if
} #/foreach

# Print out a summary

Write-Host ""
Write-Host $goodPermissions "valid permissions"
Write-Host $badPermissions "permissions needing repair"
if ($reportMode -eq $false) {Write-Host $fixedPermissions "permissions fixed"}
if ($unfixablePermissions -gt 0) {
Write-Host $unfixablePermissions "ACLs could not be repaired."
foreach ($folder in $failedFolders) {Write-Host " -" $folder}
}

# Cleanup
popd

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...