As Admin I can't access users home folder - (usershare)

How can I access user's home folders
Setting up a new server and copied users home from SBS 2003 but having setup all the users I cannot access the users home folders as Admin at the Server console.
Obviously I can login to a users PC and upload the files from the but...
This is something I need to do frequently for users.
*** Edit ***
If I enable the disabled "Administrator" account - I am then able to access the folders!
(I would like to keep Administrator account disabled)
I added Admin to the Administrators group but that didn't work either!
I suppose I I work around by enabling administrator account but would much rather allow Admin to have same rights.
ChrisS

Hi
There is a GPO that controls the Redirected Folders.... the default in SBS is to restrict users redirected folders exclusively. That means 'Administrators' can not access the files, only the specified users who own it.
Ironically i also find this restricts viewing the files on these folders in the proper backup
To fix this you need to do a number of steps.
1. First of all remove the tick from the GPO for Exclusive access to redirected folders. When this is done any new users you add, the administrators (security group) will be able to access the folders and files.
However this will not fix the ones made when the PO exclusivity was enabled. To fix this there are methods on this forum about PowerShell access, and guides, all very complicated... but neded if you can;t access your users accounts. Like you I created 3
users before noticing this GPO issue.
I found a way around it.
User 1 is restricted.
1. So go to a client computer and log on as User 1
2. navigate to \\server\redirected folders\User 1
3. Select the Documents folder and right click, properties, security
4. Add the Administrators (note the s, administrators, not administrator) and give Full Control
5. Do the same to the Desktop Folder
You need to do this for each User that is restricted, as each User that is restricted. Each User owns their Desktop and Documents folder and can therefore apply whatever security they like to it.
The difference the GPO exclusive makes is whether or not Adminsitrators are added to the security for those folders, you are just manully setting this up
You do not need to take ownership, do not need to run powershell. Admitedly if your users are remote users, and you are never at the clients with the server, then I agree maybe the Ownership and Powershell route is the way to go, but odds are you will visit
the client and be able to do this on site s the user is logged in. This is the quickest and Easiest way
Tris

Similar Messages

  • Target Mode, can't access my home folder

    I bought a new Mac Pro and am in the process of transferring apps and data from my old iMac G5...got all my applications transferred over ok via the Target mode but then....
    Ran into a problem when I tried to transfer my iPhoto Library over to new Mac Pro...
    When I put the iMac into target mode and then open the disk image (now on my Mac Pro), I am unable to access much of my home folder. As I said above, my applications folder is accessible, but the other folders have a RED minus sign on them.
    How do I fix this? Thanks-

    You went about things a bit backwards. You should have use the Migration Assistant. See http://discussions.apple.com/thread.jspa?messageID=1872713 for details. If you just got the new machine, I'd boot it with the restore disk, erase the new machine, restore the software, hook up the iMac, and use the Migration Assistant to do the transfer.

  • Sharing and Permissions for Admin Users Home Folder

    Staff user group deleted from Admin User home folder.  User groups listed are the user as read/write, admin as read and everyone as read.  If you create a new Admin user the group "staff" is listed instead of "admin"????  How do i get it back to how it was?  It also seems to be effecting stored passwords in my keychain and other apps.

    Hi, i think it depends who are you serving for, if you are just serving for a small office or home server or a big organization. The following quick thinking just came to me:
    I think cups set automatically a system  user of its own, and runs as it, so no trouble there. Cups also has the option to set users and it uses the system users as default, i think it depends in in how many printers/users your have in your server.Users that can manage cups are in the lp group. 
    For nfs every user should have their home, samba is also a good option if you have  windows computer in your network and it integrates better with graphical file  managers like nautilus in the clients side, but it is a hassle to configure.
    You should run the web server (owncloud ) as it own user, maybe you can manage to set something up for owncloud in the filesystem, but owncloud uses a database, and the users for owncloud are stored in there, and they are not system users.
    You can configure ssh for local use only enabling the corresponding subnets in your /etc/sshd.conf and optionally but recommended you can set a firewall and permissions. You can use iptables but i prefer ufw for simple setup.
    I think you should read the wiki:
    https://wiki.archlinux.org/index.php/users_and_groups
    and the other respective topics in the wiki.
    Also as an advice i know that arch linux is a great distribution, but you have to do more work to mantain a stable server. I would recommend debian or another more conservative distro, but of course it is your choice.
    Last edited by hydrosIII (2014-11-06 06:26:45)

  • Can't create an alias for User home folder for a second user

    Please help:
    I can't make an alias of a User home folder of a second user. I can successfully make an alias of a home folder of the first user. The computer says the folder is in use and to wait for some activity to complete, or that I don't have enough privileges. There are no activities happening and both accounts are administrator level. Is this a behavior of OS 10.5.6? I created alias for the two users before, but had unrelated problems and wiped the drive, re-installed 10.5.6 and now I can't do it.
    Much thanks and aloha - Rocky

    hi Petar,
    Wish it was that simple where i can just change the ID to ACT but unfortunately alot of our users like to hardcode there currentview and changing the scenario dimensions would take a big effort and alot of support work.  We had changed one of the dimension members before and we got phone calls asking why the report doesn't work for weeks.  Do you know if the NW version of BPC has that capability?
    Thanks,
    Elmer

  • How can i access my home shared videos from my iPad2 if I now have iTunes match?

    how can i access my home shared videos from my iPad2 if I now have iTunes match?

    That's exactly what I meant, but for some reason Home Sharing stopped working on my iPad2 once I activated iTunes Match.
    Since then, I waited for iTunes Match to finish setting up and scanning my iTunes library on my MacBook Pro and I restarted my iPad2. Both Home Sharing and iTunes Match are now up and running smoothly!
    Thanks for the reply!

  • TS2972 i can't access my home sharing in itunes ? :( when i fill up the apple i.d there's a pop-up window "Home sharing could not be activated because an error occurred (5506)" what's with that?

    i can't access my home sharing in itunes ? when i fill up the apple i.d there's a pop-up window "Home sharing could not be activated because an error occurred (5506)" what's with that?

    See:
    Troubleshooting Home Sharing
    Have you looked at the previous discussions listed on the right side of this page under the heading "More Like This"?

  • Can't access Users & Groups in System Preferences :(

    I can't access Users & Groups in System Preferences please help thanks

    Check the following:
    First, do you see the "User and Group" icon?
    If not, open the "presentation" menu and look under the "personalize" option to see if the icon is uncheck.
    Second, try to set a new account and see if you can access it from that account.
    Repair disk permission

  • Can not remove users home folders from TM exclude list.

    Hi
    MBP mid 2012 10.9.3.
    Been away from my TM for some time. So adjusted exclusions I have in place for regular backups. For some reason I can not remove the users home folder exclusion. I have reset TM by removing the plist. Everything reset apart from the exclusions. Any Ideas?
    Cheers.
    PJRS

    Triple-click the line below on this page to select it:
    ~/Library/Preferences/com.apple.TimeMachine.plist
    Right-click or control-click the highlighted line and select
              Services ▹ Reveal in Finder (or just Reveal)
    from the contextual menu.* A Finder window should open with a file named "com.apple.TimeMachine.plist" selected. Move the file to the Trash.
    Repeat with this line:
    ~/Library/Preferences/ByHost
    A folder named "ByHost" should open. Inside that folder, there may be a file with a long name beginning "com.apple.TimeMachine." If the file exists, move it to the Trash.
    Restart the computer and test.
    *If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination command-C. In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

  • I can not access the home page

    I have installed Oracle Portal 3.0 EA on a Windows NT 4.0 Workstation
    running Oracle 8.1.6.
    And now I can not access the home page and login from a local browser installed on the server by typing http://<hostname>/pls/portal30/portal30.home.
    Apache is still working.

    Jan-Peter,
    Obviously the browser recognizes the servername:port because your sample works. It must have a problem with the pls or DAD.
    Can you access:
    http://servername:80/pls/admin_/gateway.htm
    If yes,
    Then check to make sure you are calling the correct DAD and they are setup. You can do this through the gateway.htm page.
    If no,
    Then your 9iAS did not setup mod_plsql correctly. Check oracle_admin to see if it points to plsql.conf
    null

  • How can I access my home sharing when away from home?

    how can I access my home sharing music from my computer to my iphone
    when away from home?

    Welcome to the Apple Community.
    You can't. You can only homeshare over your home network.

  • How can I share the home folder with different accounts on the same mac?

    Hi, here's a question:
    How can I share the home folder with different accounts on the same mac?
    The whole point being not to have to install all my apps, and move all my files each time between users.
    The second thing would be to be able to modify one document on one account, and have it changed on the other account without having to copy it.
    I would like to have a pro and a private account on my mac.
    Thanks for you answers,
    Doug

    Your apps should not be installed in your home folder--they should be in /Applications where every user can access them.
    If you want to share things between users on the same Mac, use the /Users/Shared folder. Keep your home folder private. Trying to defeat the protections on the home folder subfolders just gets messy. I've never bothered to figure out all of the problems associated with it so I can't explain how to do it.
    Even with using Shared, you would need to alter the ACLs on the shared folder in order to allow both users to modify the documents.
    You must create a Group in Users & Groups and put each user in that group. Then create a folder inside /Users/Shared where you want to share the various files.
    Then, add an ACL to the shared folder that gives the group special permissions. on that folder.
    sudo chmod -R +a "<sharinggroup> allow delete,chown,list,search,add_file,add_subdirectory,delete_child,file_inherit,directory_inherit" /Users/Shared/<sharing folder>
    Replace <sharinggroup> and <sharingfolder> with the name of your group and your folder. Then, run the command in the Terminal.
    With that ACL, each user in <sharinggroup> will be able to alter the files created by any user in the group in that <sharingfolder>.
    Essentially, the client OS is not designed for true file sharing among the individual users. It is designed to isolate each user account from the others.

  • How to have the network users home folder on the server

    I have snow leopard server up and running and I want to have the network users home folder on the server, instead of it being located on the connected computers. This way the users can access their folders from other computers in the network

    In addition you have to make the sharepoint able to be automaticly mounted. The manual say this is very important.
    But you should really read the announced manual. All the manuals all filled with step-by-step instructions for modifiing many preferences... That´s my experience!
    Now I´ve got a question, too...
    My OD-Master is bound to AD. I try to use win-Accounts for workin on mac. It work pretty good, by using an group-account. In this group-account I cennect the win-accounts to instruct all the restrictions I´ve set for user-accounts.
    But this way I can´t create a homefolder on a share...
    The share(netusers) is on the same server(mac-server2) like OD-Master is running. I´ve set the path for creating homefolders in Mobility option on "//mac-server2/netusers" for the group-account the AD-user is member of.
    Is it the wrong way?

  • Apple script to delete user home folder

    I wish to run a appple script to delete all user home folders except for ladmin which is an admin account. All other user home folders need to go. Any one have a script that can do this by using ARD

    Account information is kept in NetInfo, a complex system database. If you just delete a home folder the account will still exist, and a new home folder will be created the next time a user logs into it.

  • When logging on to Windows 7 user gets a second mapped drive to the users home folder

    Morning,
    I'm working through an issue we've discovered whilst trialing Windows 7.  Our environment is setup as follows.
    Domain Controllers are Windows Server 2003
    Clients are Windows XP and Windows 7
    Windows XP and Windows 7 Clients are in seperate OU's
    All Windows XP Group Policies apply to Windows XP And Windows 7 clients, Windows 7 policies are then applied to Windows 7 clients after
    Windows 7 policies are setup such that any setting defined in a Windows XP Group policy is left unconfigured in the Windows 7 Group policy and only new Windows 7 settings have been set in Windows 7 Group Policies.
    We have users home folders mapped in their Account Directory account setting and set to H:\   to connect to
    \\domainname\dfs\home\username
    In addition we also as a fail safe map the drive via a login script using net use
    This has worked fine for years in windows XP, if Active Directory failed to map the drive for any reason then the login script would then map the home drive.
    In Windows 7 we have noticed a curious error.  We found after a period of a couple of weeks we suddenly started getting a new drive mapped.  This was identical to the H:\ drive mapping but was instead under drive Z:\.  In other words, the
    users home folder is mapped twice on h:\ and z:\.  This is not affecting any of the Windows XP users.
    I have gone through several logic reasons to ascertain why this has happened with the following findings.
    1. Originally we thought the error appeared when we tried out mapping the home drive using the mapped drives functionality new in Windows 7 group policy under preferences > windows settings > drive maps.  However, after forcing it to delete the
    Z:\ drive using this functionality we only succeeded in removing it with a group policy present to do it.  As soon as we removed that group policy the Z:\ drive came back
    2. Secondly i thought the reason we would be getting a z:\ drive when we haven't specified it anywhere is because active directory is trying to map to the H:\ Drive but it is already present therefore in Windows 7 it tries to map to a different drive. 
    Using Windows logic it tries the highest letter first which is unlikely to be in use i.e. z:\.  This makes sense because our logon script uses a net use h:\ command to map the drive and i believe by default these are set to perisistent.  Therefore
    the next time the user logs on H:\ is already mapped so the logic in Active Directory accounts maps the drive to Z:\ instead hence we end up with two mapped home drives.  To test this i altered the login script to set the drive maps to
    non persistent using persistent:no.  The logic here was that when the user logged off the drive would become unmapped so that when Active Directory tried to map the drive it would be able to use H:\.  Unfortunately this was not the case and
    Z:\ remains.
    3. Here is where i resolve the issue but i don't know why and is the bit i need answering.  If i go into my account on Active Directory and go to Profile and set the home folder drive letter to another letter i.e. change from H:\ to U:\,
    i get prompted to set full control etc and apply.  I then set the drive back from U:\ to H:\, again i am prompted for setting full control which i accept.  
    NOW when i login i no longer receive a Z:\ drive and only get an H:\ drive.  YAY, thats what i want, however, i do not understand why this is the case.  At first i thought it might be something in the active directory logic when i login to an XP
    machine and then login to a windows 7 machine.  IF you bear in mind that although i get a new profile in Windows 7 i still retain the same home folder setting.  However, after logging on an XP machine logging off then logging
    on a Windows 7 machine i still didn't get the Z:\ drive back. 
    I have tried creating a new user that ONLY receives our Windows 7 Group Policies and still they receive both an H:\ and a Z:\ drive which rules out the Windows XP policies conflicting with the Windows 7 policies.
    Does anyone have any ideas why i would get a second drive mapped to Z:\ logging into Windows 7 on a Windows Server 2003 domain? 
    Can anyone explain in more detail exactly how the Active Directory functionality works when you specify a connect to Drive letter for a users home folder?
    My current workaround is simply to add a net use command to remove the Z:\ drive.  I do not want to use Mapped Network drives using the new policy settings in Windows 7 RSAT because we have already found issues with it. 
    <input id="3daf20bf-4f4d-4a05-86da-2c30c205d580_attachments" type="hidden" />

    We had the exact same issue happen to us. No issue on Windows XP but Windows 7 mapped two home drives (F and Z). F was mapped during the login script and Z was being mapped by some unknown reason.
    We use Netapp for our storage and home drives and use a feature called CIFS Home Drive Mapping. This essentially maps a user to a folder not available through normal CIFS methods causing AD to error when setting the home drive. To get around this we use
    dsquery and dsmod to modify this attribute in the user account. This is the command we used...
    dsquery user -name %UserNameX% | dsmod user -hmdrv F -hmdir \\filer\$username$
    Notice there is no ":" after the F
    We determined the root causewas the value for the
    homeDrive attributefor the user account was set to "F" instead of "F:"
    When we updated our users to reference "F:" instead of "F" in their user, this problem was resolved.
    Use LDP or some other method to verify that the homeDrive attribute is set to "F:" (or any other letter) or you will have this issue.

  • How I Solved My "Can't Import My Home Folder" Problem While Staying Sane

    This may be a well-known work-around for Time Machine and Migration Assistant, but I didn't find any reference to it in searching in Google (which included some threads here), so I thought I'd post it in case anyone else is experiencing similar problems.
    I was having problems with some program install permissions and tried fixing them in more traditional ways without success, so I decided it was a good day for an Erase and Reinstall of Leopard.
    I didn't want to copy my entire Home directory's contents and I have 6 HDs (four internal and two external) totaling about 1.5TBs. So, to prepare for the reinstall, rather than use Backup, I copied all important files to my other drives and then I copied my Home directory to another drive in the machine. Satisfied that everything was backed-up, I reinstalled Leopard using the Erase and Install option and soon had a good system, fully updated.
    However, when I went to copy the Home Directory I kept getting errors saying that I can't alter these files and folders, even when I drilled down into the subdirectories. I didn't try copying individual files, but then I had no desire to do so given the amount of time that would take.
    I looked around but could find no good solution. However, I did come up with a workaround and this is what I did:
    First, I moved my Home Folder designation to the one on the backup hard drive by:
    1) Go to System Preferences
    2) Click the lock to make changes and enter your user password
    3) Right-Click on your User Account and select "Advanced Options"
    4) From the drop-down window, to the right of the "Home Directory" box select "Choose..."
    5) Navigate to the backup User Account home folder and select it and click "OK
    6) Relock the Accounts pane
    7) Now you can delete the "old" Home Folder under your OS drive: Users/user account
    8) Now just copy the backed-up Home Folder (that is now your real Home Folder) to the OS drive: Users/user account
    9) Repeat steps2, 3 and 4, this time selecting your now moved Home Folder in the OS drive: Users/user account
    10) Now you can delete the backup or keep it AS a backup.
    I know this is a kludgey, wrong way to do backup and that Backup is the way to go, but for those out there who don't do it or have some problem restoring it, this is a possible way around so that you don't end up having to restore everything by hand.
    This workaround may have already been discussed and well-known, but I had not seen it and am posting this in the hopes that it will help someone in trouble.
    JoeL

    joeldm,
    There is a "proper" way to do what you have done. First, one must create an account within the new installation using the exact same username and short name that was used in the old installation. Then, one enables the "root" account and logs in as root.
    Within the root account, the local HOME folder that was created for the user is placed in the trash, then replaced with a (same-named) copy from the backup. THat HOME folder copy will be onwed by root, so this command must be run in Terminal:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">chown -R username:staff /Users/username</pre>
    In the above command, all instances of "username" are replaced with the user's short name. For example, if the user's name is "fred," the command would be typed exactly like this:
    <pre style="overflow:auto; font-family: 'Monaco'; font-size: 10px">chown -R fred:staff /Users/fred</pre>
    The command is executed when <RETURN> is pressed. NOTE: The specific command listed above applies only to 10.5.
    One would then log out of the "root" account, and into the account in question. If all seems well, one would log back into the root account, empty the trash, then log out of and disable the root account.
    Alternatively, if there is a Time Machine backup that can be used, the Time Machine interface can be used in the root account to replace the trashed HOME folder, instead of copying manually in the Finder. This would generally be a better method to use, if possible.
    Scott
    EDIT: If one wishes to replace/restore only certain portions of a HOME folder, this is possible. The same methods would apply to only limited segments within a HOME folder. -s

Maybe you are looking for

  • Memory slots on the latest dv6t quad edition?

    I just submitted my order on a customized dv6tqe. I have chosen the i7-2720qm processor and there is a free upgrade to 6GB memory. Since I heard that the Sandy Bridge supports 3 channel, could anyone tell me if it is a 4+2GB combination or a 3*2GB co

  • FI_CA: Function FKK_OPEN_ITEM_SELECT_WITH_DATE

    Hi guys, I want to use the FM FKK_OPEN_ITEM_SELECT_WITH_DATE to retrieve the open items of an contract account, but I'm not sure about the function of the flags I_WITH_INSTPLN and I_ALLITEMS. Could anyone explain a little about the behavior of the FM

  • My apple tv saying not connected to itunes - yet it is

    my apple tv shows all the icons of movies etc, plays some You tube stuff but not others. SHows movies icons and pics, but when i try rent it shows rented, but when it i try play the movie it says not connected to the internet, yet it is I have the la

  • How to get a message from call transaction in RFC call

    Hello : I would like to ask one favor i make a 2 call transaction in a RFC funtion when i make the first CALL TRANSACTION using te next statement.     CALL TRANSACTION 'F-43'       USING bdcdata MESSAGES INTO messtab2 OPTIONS FROM l_fromopt. I recive

  • A set from a set of sampled data from a thickness sensor.

    A  set from a set of sampled data from a thickness sensor. The samples are stored in an appropriate array of up to 100 elements. The values represent the depth of the insulation around a particular cable. The thickness can vary from 0-4mm represented