Permissioning and folder sharing issues on domain

We are new to Active Directory.  I am experimenting with folder and sharing permissions in an effort to get to where we can secure network folders for access to only certain individuals.
I am running into inexplicable behavior.
On a domain joined server, I have created a folder called "for ITADMIN".  This folder should only be accessible to members of the ITADMIN domain security group.  I disabled inheritance on this folder first.  Then, in the Security
tab, I have set it up such that there are only two security principals in the ACL: SYSTEM and ITADMIN, both of which have full control.
On the Sharing tab, I went to Advanced Sharing and clicked the Permissions button.  Here, I set my sharing permissions.  There is only one security principal in this ACL, ITADMIN, and ITADMIN is granted full control.
At this point, I am still logged in to the domain joined server with my own user account.  My user account is a member of ITADMIN.  I can open Windows Explorer and browse through the "for ITADMIN" folder freely.
Now, I log in to our Domain Controller with my user account.  In Windows Explorer, I type in the UNC path to the domain joined server hosting our shared folders (\\machinename).  I see the shared folder "for ITADMIN".  When
I try to go into it, I receive an error:
"Windows cannot access \\machinename\for ITADMIN.  You do not have permissions to access \\machinename\for ITADMIN.  Contact your network administrator to request access?
I am a member of the ITADMIN group.  ITADMIN is the owner of the shared folder, has Full Control security permissions, and Full Control sharing permissions.  Why in the world is this behavior occurring?
Additional Info: Could this be a problem when trying to access shares from the domain controller?  While I don't anticipate needing to do this from the DC on a production basis, it still seems bizarre.
Additional Info: my ITADMIN group is a global group.  Could that be posing a problem?

Nevermind.  I neglected to log out and log back in after making permissions changes, thus my account's security token was not getting updated.

Similar Messages

  • Does simple file and folder sharing on an iMac work with OSX Server?

    Hi There
    I wonder if I should install OSX Server on an iMac wher several users work on the same files and folders.
    My question - before I do something I might regret:
    Does simple file and folder sharing on an iMac within several users really work with the help of OSX Server?
    All I want to be able to do:
    Admin creates a new folder1 and gives it read- and write access for user1 and user2.
    User1 creates a subfolder1 in folder1, and a document1 in subfolder1.
    User2 edits document1. Later Admin edits document1.
    All these simple editing of files and folders (and subfolders) within a main folder should be possible. This is not possible now.
    Is everything clear? I'm not a network specialist or something, I just want to give some co-workers access to some data on my computer without problems.

    So what you need are recursive permissions.
    I suggest you create a group and add user1 and user2 to that group. You can name that group whatever you want, but for now i will call it FSUsers
    Execute this in terminal. Replace FSUsers with your new group
    sudo chmod -R +a "FSUsers allow list,add_file,search,add_subdirectory,delete_child,readattr,writeattr,readextat tr,writeextattr,readsecurity,file_inherit,directory_inherit" /Users/Shared/*
    Replace /Users/Shared with the location of your shared folder. Make sure you keep the /* at the end (this allows all subfolders and files to get the same permissions.
    If you need to add people to the share just add them to the FSUsers group, the FSUsers group should should also be allowed in the sharing preferences.

  • E3000 file and printer sharing issues

    Yes, there is at least one other thread on this but it looked a bit stale.
    Last Friday I replaced my BEFSR41 router and WRT54G wireless access point (which had gone brick on me) with an E3000.The E3000 is configured as a DHCP server at 192.168.168.65 with a scope of 66-115. The only other non-default setting is that I opened up the custom port for my slingbox.
    Prior to making the switch, I had several network shares on an XP desktop that I used frequently from my Vista laptop. Now, however, I can no longer even "see" any other computer from any of the computers on the network, much less access their shared folders. In other words, if I view the network from any of these machines, the only machine that shows up is the machine itself. Everything else (internet access, slingbox, a print server) is working just fine.
    One of the suggestions in the other thread was to turn off Norton Internet Security, which is of course not a viable option. However I did check the settings, relaxed the network default to "Shared", and raised the XP desktop to "Full Trust". This had no effect.
    I pinged the various computers, and was able to do so by their IP addresses, but not by their computer names (that worked with the old router). On a hunch, I tried creating a mapped drive, and that also worked when I used the IP address, but not when I used the computer name.
    So - there's nothing wrong with the network configuration, or with how the shares are set up, and Norton isn't the problem. The only problem seems to be that names aren't being resolved, which could be affecting windows discovery, too. Did the BEFSR41 provide some local DNS functionality by default, and the E3000 doesn't? Is there an option I need to enable? If so, I can't find it. Perhaps I should explicitly add the E3000's internal IP address as a third nameserver??
    A note on the "support" I tried to get before I turned to the forums: The "Chat agent" asked a bunch of questions, misunderstood my configuration and my problem, and once he finally did understand said "we don't support file and printer sharing". It took me several more questions to learn that he really meant that the Chat facility isn't the place for these questions - I had to call the 800 number. I did that, and after several minutes on hold, reached an agent. After going through everything again, and with the rep going on hold several times to "speak to his supervisor", he said it was "beyond his competence". I was eventually told I had to call another FEE-BASED service. I told him that was unacceptable.

    Ok, another update and possibly some clues.
    I was curious why at one point, when all the computers were in Workgroup2, that "Workgroup" still showed up in Explorer under the list of networks, but only on the two XP machines. Netscan showed this group association as well, which I then realized was the E3000 itself, in its role as a [I]potential[/I] NAS server. However there was no storage device attached.
    Could this in itself cause the access error? If so, should users be advised that if they don't plan to host any storage, that they should to go to the E3000 Storage Administration page and change the workgroup name to something other than their actual workgroup name?
    In my case, I changed it to "Workgroupx", though perphaps something like "StorageGroup" would be more meaningful, especially if the Workgroup computers could still access any storage I might install in the future.
    Anyway, I repeated my original approach (after the above change and a router reboot), and at least got my original Workgroup reestablished to the point where the XP machines not longer get access errors, and most machines can access the shares on the XP desktop. The steps I used on each machine were:
    remove any shares I had set up on any folders
    uninstalled the File and Printer Sharing service
    Accessed Computer Name properties page to change the workgroup name
    Shut Down
    After all 4 were done, I reversed the process:
    Started computer (now coming up in new Workgroup)
    Reinstalled File and Printer Sharing service
    Checked visibility
    At this point, the XP machines could see each other, and the Win7 and Vista machines could see each other, but initially these two cliques wouldn't interact.
    Next I re-added the shared folders on the XP desktop, and the XP netbook could see and access them. After about an hour, the Win7 machine joined this clique, and could also access the shares. But six hours later, the Vista machine is still clueless. Netscan shows everything of course, and I used it to set up a mapped drive on the Vista machine to one of the shared folders.
    Other possibly relevant facts:
    The was all working fine with the BEFRS41/WAP54G combo
    I can ping all machines by IP address, but not by name
    On the Vista machine I can set up mapped drives to the XP's shared folders, but again, only by IP address.
    At one point I removed NWLink from the XP desktop. Now, nbtstat -r only shows the printserver's name being resolved.
    The two XP machines, being SP3, lack the LLTD responder.
    So,
    Is it possible the NetBIOS in NWLink was providing some kind of name caching? If so, should I reinstall the protocol driver (I don't think it is available on Win7)?
    Should I request and apply the KB922120 hotfix to get LLTD onto the XP machines?
    Perhaps in the morning, "by name" access will have returned, as it did on my first go-round. Needless to say this has been a real pain, what with all the reboots required. At least now I remember to hit F8 so I can select Safe Mode with Networking...

  • ITunes 7 - 2 user accounts 1 music folder sharing issues

    I just downloaded iTunes 7 this afternoon. I imported some music from my CDs into my account. My wife and I have a shared music folder. I then logged onto my wifes account and added the music to her library. Her accound moved the music files from the original folder to an Unknown Artist folder losing the file information. Does anyone know why this is happening?
    I apologize if this is topic has already been posted.
    r/
    SNeck
    MacBook Pro1,1   Mac OS X (10.4.7)  

    If you have a folder on the hard drive called anything you want (Shared Files for example) and leave it in the root directory, anyone should be able to access it. If one of the user accounts doesn't have administrator access, writing to that folder may be an issue.
    To fix this, control-click (right click) and select get info. Go to the permissions tab. Use the little arrow next to 'Details' to make sure it shows the details. Select the group 'everyone' and allow them to 'Read and Write'. Click on the checkbox 'Apply to enclosed items'. You'll need to do it from an administrator account.
    Should sort you out.
    Karn.

  • Multiple Node Manager Instances and servers sharing the same domain home.

    Hi,
    We have a 8 man server weblogic cluster spread over 4 machines. Each machine runs 2 man servers each.
    Each of the machine is configured to run node manager.
    We use shared storage accessible to all 8 servers and all 8 man servers have the same domain_home.
    Lets call it W:/domain
    Now the problem we are facing is that node manager running on 1 machine is trying to access/control a managed server on a different machine after a machine restart.
    eg.
    ManServer1 Home : W:/domain/servers/server1 ====> runs on Machine 1
    ManServer2Home : W:/domain/servers/server2 ====> runs on Machine 2
    Problem is node manager on machine 1 is trying to restart man server 2. The path W:/domain/servers/server2 is accessible to Machine 1.
    After a restart, what I assume is happening is that the nodemanager is checking all servers folder under Domain_Home/Servers and trying to restart servers instead of restarting only those which it should start. The config file has the server and machine assignment done correctly. Is there a way to make this configuration towork. Or do we need to create different domain_home's for different man servers like
    Domain_Home for MS1: W:/domain/MS1 ( Server Home would be : W:/domain/MS1/servers/MS1)
    Domain_Home for MS2: W:/domain/MS2 ( Server Home would be : W:/domain/MS2/servers/MS2)
    Regards,
    Atheek
    Edited by: atheek1 on 03-May-2010 00:27

    Thanks - We have tried putting 2 dad entries in file, but not sure how you connect. You only specify a port number, so how does it connect that to a db???

  • File and folder sharing and permissions.

    Many times when we copy files or folders to another mac computer, their permissions change, and many times the new user can not open it, until the file or folder permissions are changed. It start happen with MacOX 10.5, and still is happening with 10.7, with 10.5 we were waiting for the patch, but it never arrived, then I think is not a mistake for apple software developers??. But how can I solve this issue? the people need to interchage files and folders by USB, or network, and need to work as soon as possible with that materials and not loose time changing permissions. Someone knows what can I do to solve it?

    Did you log out of one account and into the other or just used Fast user switching?
    Is the permissions set to anyone?
    When you move data to teh Shared folder is it copied or just moved?
    If copied then it's not a folder both can access, just a way station like a USB thumb drive that things are coped too and off of likely.
    You can run this #5 on each user account to reset the user permissions once they are taken back out of the Shared folder
    Step by Step to fix your Mac

  • File and Folder Security Issue

    Hi,
    I'm facing some problem in my windows server 2012 r2. Problem is, when i set a users permission to modify a folder and it's content then that user can delete this folder and it's content. But I want user can write, edit a file (like .doc or .xls) but he
    cannot delete this file. Is it possible?
    Regards,
    Mahfuz

    Hi,I have been facing the same problem.
    The security measures which were already mentioned here will not gonna work for MS office
    file extension because without providing modify permission,its not possible to edit them as this protection is working on this way "edit=delete+create".
    So without providing delete option,is there any other way out to manage the staffs?Please let me know.
    Thanks,
    Ashief Ahmed

  • Bluetooth Network and Internet sharing issue

    I'm trying to set up a network through Bluetooth between two computers having the latest Toshiba Stack installed, and to share the Internet connection with the second computer.
    On the firs computer I've set the Internet Connection Sharing, and because of this it automatically sets the TCP/IP adresses for the Bluetooth Personal Area network (192.168.0.1).
    On the 2nd computer, i've set everything to obtain it automatically. Firewalls (Kaspersky) disabled.
    When I connect the 2 Bluetooth devices, everything looks fine, the 2nd automatically obtains the IP adress, I can ping both computers, and the Internet also works on the 2nd computer, for a few seconds! After that, it appears like the 2nd computer is disconnected from the network... what could be the problem?
    In the event viewer under the System tab, I've found Informations like these:
    2nd comp:
    The system detected that network adapter \DEVICE\TCPIP_{E44D18EB-91F5-4... was connected to the network, and has initiated normal operation over the network adapter.
    The browser has forced an election on network \Device\NetBT_Tcpip_{E44D18EB-... because a master browser was stopped.
    and at 1st comp also appeares this:
    The system detected that network adapter Bluetooth...Area Network - Packet Scheduler Miniport was disconnected from the network, and the adapter's network configuration has been released. If the network adapter was not disconnected, this may indicate that it has malfunctioned. Please contact your vendor for updated drivers.

    ================================================== =========================
    Interface List
    0x1 ........................... MS TCP Loopback interface
    0x2 ...00 17 31 27 e6 10 ...... Intel(R) PRO/1000 PL Network Connection - Packet Scheduler Miniport
    0x20004 ...00 60 52 0b 53 e3 ...... Realtek RTL8029(AS) PCI Ethernet Adapter - Packet Scheduler Miniport
    ================================================== =========================
    ================================================== =========================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 195.222.104.193 195.222.104.219 20
    127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
    192.168.0.0 255.255.255.0 192.168.0.1 192.168.0.1 30
    192.168.0.1 255.255.255.255 127.0.0.1 127.0.0.1 30
    192.168.0.255 255.255.255.255 192.168.0.1 192.168.0.1 30
    195.222.104.192 255.255.255.224 195.222.104.219 195.222.104.219 20
    195.222.104.219 255.255.255.255 127.0.0.1 127.0.0.1 20
    195.222.104.255 255.255.255.255 195.222.104.219 195.222.104.219 20
    224.0.0.0 240.0.0.0 192.168.0.1 192.168.0.1 30
    224.0.0.0 240.0.0.0 195.222.104.219 195.222.104.219 20
    255.255.255.255 255.255.255.255 192.168.0.1 192.168.0.1 1
    255.255.255.255 255.255.255.255 195.222.104.219 195.222.104.219 1
    Default Gateway: 195.222.104.193
    ================================================== =========================
    Persistent Routes:
    None

  • IMac and internet sharing issue

    Under System Preferences_Internet & Sharing_Sharing, I have the internet sharing box checked, along with screen sharing. Whenever I turn on my computer, the internet sharing is disabled, although the box is still checked. Once I re-check the box, it starts up again. What gives?

    Everyone I found the answer after I posted my own comment re localhost...got me thinking.
    I checked /etc/hosts file and in there was a loopback to localhost
    127.0.0.1     somewebsite.com
    WOW...how the heck did that get entered as I never edited this file??
    Now all works fine.
    Thanks everyone for your assistance.
    Here is a link to where I originally found the clue

  • HT1727 How do you grant permission for home sharing and authorizing?  My mac did home share, but now says, "The required directory was not found or has a permissions error", when I try to authorize.

    How do you grant permission for home sharing and authorizing?  My mac did home share, but now says, "The required directory was not found or has a permissions error", when I try to authorize.

    OK, I just got off of the phone with Apple and still no joy. They had me try a few things that did not work, then told me to Archive and Install, which did not either. Anyway, thanks for the additional help very note worthy, but still no joy. Also an email to iTunes Support took me here
    http://docs.info.apple.com/article.html?artnum=93061
    I have a Users/Shared folder but since the files we are talking about are invisible, I can see how it is structured.
    And by the way I tried this one
    http://discussions.apple.com/message.jspa?messageID=3577004#3577004
    and it did not work. However, when I install a fresh copy of Tiger on the external it did authorize the computer and was able to play the downloads. But coping the invisible file to my boot drive was not successful. But , like I said the music did play when I started up from the external. So I guess that may be my only solution, unless someone can tell what the correct directory is and where it for iTunes downloads.

  • Can too large a folder cause issues and effect performace of my Mac Pro

    Hi, I have a 180 gb folder filled with important data within my Home folder. This folder has a many subfolders as well. The folder is on my startup drive and where I have Snow Leopard installed. Can too large a folder cause issues with my mac and effect performance? Thanks

    another way to ask, would you make better use of, and improve I/O and performance, if you used your other drive bays? yes.
    Boot drives with even less than 50% free is probably not a good idea. All depends on whether 200GB is on 1TB or on 500GB drive. And how fragmented free space even.
    Lifting, loading and writing or copying 4GB files of course does have an impact, so if you work with 2GB files in CS5....
    Having a dedicated type boot drive, media drive (and isolate media and library files) as well as scratch drive is normally done with Mac Pro.
    The biggest bang in performance: lean mean SSD boot drive.

  • How to set up permission for portal objects and folder

    Hi All,
    We are implementing EP 7.0. For creating portal objects, I have assigned "Super_admin, Content_admin, System_admin and User_admin" role to my userid and created iviews, roles and folder.
    During SAP audit they asked us to open a Iview to show the permission,   the below are the value shown in permission editor.
    Role Name           ====== Administrator ===== End  User ======Role Assigner
    Everyone             ======  Read            ======Yes        ====== No
    Super_admin_role ====== Owner            =====Yes         ======Yes
    SAP asked us to change the permission and said "Super_admin_role" should not be used, they asked us to create a group or role and assign. We are not clear what SAP wanted us to do.
    Can any one let me know how this permission needs to be given and whether "Super Admin" role can be assigned to a userid.
    Thanks in advance.
    Rgards,
    H.K.Hayath Basha.

    Hi Michael,
    I didn't create any role. I will let yo know what I have done so far.
    1. Created a group called "ADMIN_GROUP".
    2. Assigned "SUPER_ADMIN" role to group "ADMIN_GROUP.
    3. Assigned userid "ADMIN_USER" to group "ADMIN_GROUP".
    4. Opened the persmission of "PORTAL_CONTENT" folder and added group "ADMIN_GROUP" and set this group as "OWNER",  "END_USER" check box is ticked and "ROLE_ASSIGNER" check box is checked.
    5. Removed the role "SUPER_ADMIN" from  group "ADMIN_GROUP".
    6. Logged into portal using "ADMIN_USER" created a folder called "TESTING". Then opened the
        permission editor for the folder "TESTING", it showed three record
        "ADMIN_GROUP"           === OWNER  === 'X' === 'X'
        "EVERY_ONE"               === READ     === 'X' === ' '
        "SUPER_ADMIN_ROLE. === OWNER  === 'X' === 'X'
    7. I am not able to delete "SUPER_ADMIN_ROLE" from the permission editor, as it is greyed.
    With the above steps what I have achieved is I have given permission to group "ADMIN_GROUP". Is this what we need to do. Did I did anything wrong.
    Regards,
    H.K.Hayath Basha.

  • Multiple Domain 404 and Folder Setup

    Hi All,
    Hope everyone has had a nice weekend.
    I am currently setting up www.sunnyheat.fr for a client and we are hosting it of the www.sunnyheat.org.uk system as they are the same company but require multilingual websites. They did not want to go down the google translate route hence having it done it proper french.
    The France website requires a 404 page in French, but the default 404 page is set to the standard system page which is in English.
    My other question is, how have you set your folder up for multiple domains that require seperate content and pages?
    At the moment I have a FR folder in the root and all the pages are setup in that, is there a way to have two seperate root folders?
    Look forward to your responses and how your doing it!
    many thanks
    Asad Ali

    Thanks Liam.
    What is the full scope of picking a country do? Right know I could see how it might effect ecommerce sites because of currency. But for non-ecommerce sites does the 'county' designation do anything?
    From chat I was just told:
    "Country and the culture define the language for the site and time zone for the site."
    "it also defines the currency and taxes etc."
    Wondering if this is documented somewhere and I'm just missing it. Would love to the full definitive answer the clearly states topics like the 404 pages, etc.

  • 10.4.11 OD and 10.5.4 AFP Home Folder Server Issues

    Hello,
    We have recently changed all our 10.4.11 AFP servers to 10.5.4 after some initial testing, we have left the OD master and OD replica on 10.4.11.
    Although we can login existing users happily using the upgraded servers, when we create a new user we can not successfully login as the new user and mount the home folder, after login a pop-up appears stating that the home folder for the new user can not be located in the usual place.
    I have also noticed that when I use 10.4 WGM I can see all the users and all looks normal. When I use 10.5 WGM and view the users I only see our original users, but then I look in the inspector view and find that all the users are there.
    Very strange stuff going on, is anyone else having this issue or have any ideas?
    Thanks

    Hi,
    We sorted the problem, one issue was that we did not have the hostname set to the FQDN that was needed for the home folder mounts, this stopped the proper traversal of the /Network/Servers symbolic link. And the other issue is that on our 10.5 afp servers we needed to have the 'Open Directory Server' option set for LDAP Mappings in Directory Utility to be able to see all users in the 10.4 OD.
    J

  • Is there any way to recover lost files and folder? I shared my desktop and suddenly I lost every single file in it.

    Is there any way to recover lost files and folder? I shared my desktop and suddenly I lost every single file in it. I have a MacBook Air.
    Processor  1.8 GHz Intel Core i5.
    Memory  4 GB 1600 MHz DDR3

    From your backup

Maybe you are looking for

  • How do I get Flash Player unblocked

    how do I get Flash player to work?

  • Unknown sync error -- Tried everything (?)

    I've recently switched from Chrome to Firefox to try and get as far away from Google as possible. There, I never had any issues with syncing across devices and platforms. On my Windows desktop, syncing never fails. On my MacBook Air, it always says,

  • I cant access Itunes store or itunes help

    Its not blocked on any firewall and im connected to the internet. I've changed hosts file and everything in the troubleshoot section, still not working, please help. (Build 8250) Alienware M11xR3 iTunes 10.6.1.7 QuickTime not available FairPlay 1.14.

  • Link Aggregation ... almost there!

    Hi all After struggling with Link Aggregation on Mac OS X Server to Extreme X450 switches we are almost there. We've now managed to get a live working link where the Ethernet 1 and 2 arew green and the Bond0 shows both links as active, and finally th

  • Odbc drive

    Odbc drive has returned an error (SQLExecDirectW). State: HY000. Code: 10058. [NQODBC] [SQL_STATE: HY000] [nQSError: 10058] A general error has occurred. [nQSError: 27004] Unresolved table: "Paint". (HY000) Please could you help me with this?