NTFS Permissions

tvanduzee

Member
May 8, 2013
25
0
0
Windows 2008 R2
I have a shared folder that employees company wide use. I have permissions setup so that not everyone can see all folders.. Works fine.

However, there is one folder structure I seem to be having problems with.. All users that can see this folder have read/write/modify access because they need to contribute autocad and solidworks drawings. Problem is that some "un-informed" users move files from place to place and to other users; they seem to have been deleted. Last time, it was 65000 files. I would like to allow the users to read/write and change the files, but I want to prevent deletion (if my understanding is correct, when a file is moved to another location, it is copied then deleted from the source). Either way, I don't want end users to move or delete.

Any idea how I can get this to work the way I need?

Thanks
Terry
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
From my experience, there are a lot of files that can't be modified without a user having "delete" access to the folder. If memory is serving me correctly, this applies to Microsoft Office files (doc/docx, xls/xlsx, etc) because of the way the Office Products interact with the files when they are saving changes.

I'd love to hear if this can be done, but as far as i know, it's not a possibility.
 

hamunaptra

Senior member
May 24, 2005
929
0
71
Try explicitly setting the Advanced permission "Delete" to deny for the users u wish to not allow to delete the file.
So, right click -> properties -> Security -> advanced -> change permissions -> uncheck inherit security settings -> select remove or add (dependin on ur preference either gives you clean slate or leaves the inherited ones by default)
Next, if working w/ the remove option, add your group / users -> select full control (or w/e ur preference of settings) then in the deny column check Delete. It will reflect 2 diff security policies then one labeled (special) the other labeled (delete)

From there users should be able to read / edit .. but not delete them.
 
Last edited:

dawks

Diamond Member
Oct 9, 1999
5,071
2
81
From my experience, there are a lot of files that can't be modified without a user having "delete" access to the folder. If memory is serving me correctly, this applies to Microsoft Office files (doc/docx, xls/xlsx, etc) because of the way the Office Products interact with the files when they are saving changes.

I'd love to hear if this can be done, but as far as i know, it's not a possibility.

You are correct in that 'delete' is required to modify files. I always get them mixed up but there are two Delete options. One is Delete, 2nd one is Delete Subfolders and Files.

Giving a user permission for one of these will allow them to modify the files, but not delete them.

I ran into a similar problem where users would randomly delete someone else's entire shared folder. So I had to find a way to allow people to modify but not delete files.
 

hamunaptra

Senior member
May 24, 2005
929
0
71
hehe, I guess thats why there are shadow volumes =P, right click, restore previous versions...rofl
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
You are correct in that 'delete' is required to modify files. I always get them mixed up but there are two Delete options. One is Delete, 2nd one is Delete Subfolders and Files.

Giving a user permission for one of these will allow them to modify the files, but not delete them.

I ran into a similar problem where users would randomly delete someone else's entire shared folder. So I had to find a way to allow people to modify but not delete files.

I'm not so sure about that...
"Delete" lets you delete the object that you're setting the permission on (the root shared folder, for example).
"Delete SubFolders and Files" lets you delete any child objects. So, a user might not be able to delete the root share, but they can still accidentally delete all of the files/folders inside it.
 

tvanduzee

Member
May 8, 2013
25
0
0
What I did, and I can change it if I need to, is to add "deny"/delete and deny "delete folders/subfolders" to the group that has read/write on that folder structure. This way the most restrictive will take place, which is to allow full control but deny deleting. I then allowed to to propogate to all sub items of that folder.
I will have to monitor it and see what happens, but like I say, I can always change it back if I need to.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
What I did, and I can change it if I need to, is to add "deny"/delete and deny "delete folders/subfolders" to the group that has read/write on that folder structure. This way the most restrictive will take place, which is to allow full control but deny deleting. I then allowed to to propogate to all sub items of that folder.
I will have to monitor it and see what happens, but like I say, I can always change it back if I need to.

If people are just copying files to it manually you may be fine, but as seepy83 says, the delete right is largely useless these days because lots of apps save files by writing the whole thing to a new temp file and once that succeeds they delete the original and rename the temp to the original name. They do that because there's no way to make a full file write/update atomic so that's the safest method to avoid data loss.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |