Permissions for file sharing to Windows users

Greetings, I would be very pleased if someone could help me with file sharing permissions for Windows users of a Mac mini file server running Snow Leopard 10.6.1 (not server).
I have a folder in my root directory, lets call it Project, that holds a series of 10 sub folders, say 1 through 10. Some of my users I wish to have read/write access to the whole Project directory, and, having enabled file sharing in System Preferences (and SMB for Windows), I did cmd to get info on the Project folder, ticked sharing, added the users (whose user accounts I had replicated on the Mac from their Windows machines), gave them read/write access, and then was able to map a drive to Project in their machines. All good so far, notwithstanding an hour tussle with a Vista laptop . The other user 'groups' were set the following permissions: me - read/write; Admin - read/write; Everyone - no access; which seemed sensible.
Then, when I wanted to only share say sub folders 4, 5 and 6 with other users, who will not have access to the whole Project directory, things were not as straight forward. I followed the same procedure as above, but for the particular sub folders. However, I think they are only able to see them if I provide read or read/write access for Everyone to the parent Project directory. This of course then lets them at least see all the other folders I do not want to share with them. I don't seem to be able to remove the Everyone group from the Project directory, which occurred to me might resolve this.
Any thoughts? Thanks.

"On the way down, it seems to me that you still can prevent that user from using folders that he or she is not supposed to use by setting appropriate permissions."
I don't think this is the case. If I allow someone read & write access to a folder because they need to have read & write access to two of three subfolders, I cannot deny them (at least) read access to the third folder.
In respect of a particular folder:
1. You can only assign read; read & write; or write (drop box) to an individual user; and
2. You can only assign No Access to everyone.
Do I need to use Snow Leopard Server to be able to assign No Access to a particular folder for an individual user?

Similar Messages

  • Can't select user for file sharing with windows

    I'm trying to share my MBPr over my LAN with my windows 8 desktop. When i go to the file sharing options, under "Windows File Sharing" section, the user account i want to share (my main account) is greyed out, so I can not select it. The other user account is selectable though.
    Any reason why I can't select my main account??

    wow, is that all it took? I spent several hours on support chat who ultimately made me create a new user account and import all my old account data over to that one. It worked, but would have been way easier to just change the password. Oh well. It's fixed now...

  • How to set permissions for files created by Windows on OS 10.8 volume

    I am in process of upgrading from an iMac with OS 10.6 to an iMac with OS 10.8.  In my office network, I store all files on my iMac and let the Windows PCs act as workstations to read/write onto the Mac.  (It's simpler to have all files centralized in one location, and only have to be concerned about backing up one volume.)
    When I had OS 10.4 and OS 10.6 any newly created file saved by the Windows PCs onto the Mac could be opened by the Mac.
    But with OS 10.8, I can not open newly created files from Windows.  The file permissions for the newly created files from the Windows PCs are: 
         PCUser = read/write;  Everyone = no access.
    What do I need to do so that newly created files from the Windows PC (currently Windows 7) can be opened by the Mac, without having to use Get Info to reset the permissions each time?

    You could try adding this Access Control Entry (ACE) to the folders you let them save to:
    sudo chmod -R +a "accountinggroup allow delete,chown,list,search,add_file,add_subdirectory,delete_child,file_inherit,directory_inherit" /Path/to/topmost/folder
    You first need to create a group for all the sharing people you want to have access to that folder, if you don't already have one. In the example, "accountinggroup" is the group, so change that to whatever you want to use.
    The ACE allows them full access to the files in the folders. If you want to limit that, remove the option (such as delete).
    You create Groups in Users & Groups System Preference just like creating a new user. Just change the account type to Group.
    If you want a GUI to do the settings, try Sandbox.  It's got a few glitches in the Interface, but it seems to write the ACL correctly. One glitch is selecting the Group or User. I had just a list of Continuing in the popup menu. I typed in the Group name I wanted and it worked. Some errors pop up as you traverse the file hierarchy, but you can dismiss them.
    Here is an old hint, which gives a little background, and some other options: http://hints.macworld.com/article.php?story=20090219133314985
    The Server tools would allow you to set this up more easily, but if this is all you need as the server, I don't know if it is worth it.

  • I want to use iChat video and file sharing with Windows users

    Nowadays, iChat is compatible with AOL/AIM, Google Talk, Jabber, Mac.com and MobileMe instant messaging services. I know that Yahoo Messenger support will be available soon in Mac OS X Lion.
    I tried using AOL/AIM and Google Talk natively in iChat in order to talk with Windows users which were using Google Talk application or web chatting (Me from: Google Talk - My friends from:  Google Talk, and Me from: AOL/AIM - My friends from:  Google Talk), but videoconference and file sharing were not available.
    I also tried Windows Live Messenger in iChat via Jabber intermediate, but it is not efficient and doesn't work for videoconference and file sharing.
    So, which IM service combination I should use to chat with Windows users in order to be able to use videoconference and file sharing using such a great app like iChat?
    Thanks you.

    Hi,
    A lapsed Trial or lapsed Paid for MobileMe account will not work in any fashion, as a Screen Name in iChat/AIM apps or as a Email.  (Of course it is no longer an Valid Apple ID either).
    Given that Google is a Jabber server iChat will Video (or Audio Only) Chat Jabber to Jabber.
    With a Valid AIM name (AIM, MobileMe or @mac.com) then it is supposed to work to AIM on a PC
    This tends to vary from person to person as to success.
    From AIM version 6.5 AIM introduced a Send as Typing feature called "Real Time"
    It does not work to iChat and in fact also has to be turned Off in the Buddy List at the AIM end for Video or Audio chats to work.
    The AIM app also has to be allowed through the Windows Firewall as an Exception, preferably with UPnP enabled as well and UPnP enabled in their Router.
    Trillian is a paid for App for PCs that provide an alternative.
    Recently theri site offered 3 windows versions
    The Pro version of verion 3.2 (known to work), a version 4 and a version 5 in beta.  The version 3.2 used to have a free Text chat version and only the Pro version was needed to Video.
    Until the site was reorganised the 3.2 version was "On Sale" at a reduced price.
    It seems version 5 is now out of beta
    They are still separating out a Pro version.
    It is a multi-service client
    There is also a Mac version although I have not tried it.
    I am not sure what you mean by "Manage" your MSN Contacts.
    How about using a MobileMe expired account screen name for using iChat with Windows-Google Talk users? Should I expect the same incompatibilities?
    I have already addressed part of this. The fact the name will not work full stop.
    However one way of reading this is that you are thing of linking AIM and Jabber (Google) Buddies in one Buddy List
    Directly in iChat this cannot be done - unless you are the one with the Jabber Account and an AIM Transport set up.
    You would be subject to the same Text Chat only restrictions.
    It is a bit like the fact your phone line can be used for Fax, Telephone and DSL broadband. (in fact mine does TV as well)
    You granny would not be able to talk to your Fax machine if that happened to answer the call.
    Her Fax machine might be able to communicate with your computer if you had an active Fax app on there, and a dail-up modem active to answer.
    10:06 PM      Tuesday; May 24, 2011
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro 2Gb( 10.6.7)
     Mac OS X (10.6.7),
    "Limit the Logs to the Bits above Binary Images."  No, Seriously

  • Force permissions for file sharing (acl)

    Hi all
    I'm trying to set up a server so that multiple users can share files over sftp and ssh.
    To do this I did the following:
    0. Mounted an ext4 partition with acl enabled
    1. Created a folder with an appropriate group (say 'sharing')
    2. Set the gid flag on it (chmod g+s)
    3. Added all the users to the sharing group
    4. Setup acl on the folder :
          setfacl -dm u::rwX,g::rwX,o::- /path/to/folder
          setfacl -dm m::rwX /path/to/folder
          setfacl -dm g:sharing:rwX /path/to/folder
    Now, whenever I create files or folders inside my shared folder they have the correct permissions (660) and the sharing group. However, when the files are *transferred* in via sftp, scp, unison etc the acl permissions do not take hold.
    With unison I've tried setting perms=0 and dontchmod=true but this just gives all files -rw------- permissions.
    SFTP mirrors the original permissions but is 'masked' by acl: i.e. a 666 file is set to 660 (as expected) while a 644 file becomes 640 (what i want is for it to be set to 660)
    Is there any way to force permissions (with acl or some other tool) on files added or transferred into a folder regardless of the software doing the transferring? Ideally, I'd like it if this were something that happened completely on the server and did not depend on me configuring client tools.
    Thanks!
    Last edited by harshad1 (2014-05-22 15:09:10)

    rune0077 wrote:
    Change the umask of the sftp process.
    In your sshd_config there's a line that says:
    Subsystem sftp /usr/lib/ssh/sftp-server
    Append -u 0002 (or whatever umask you want) to the end. Like this:
    Subsystem sftp /usr/lib/ssh/sftp-server -u 0002
    First thing I tried. Doesn't seem to work.
    I should mention that I'm using sftp-chroot and I've used mount -bind to allow sftp users access the the (shared) data folder from with the chroot.
    I don't know how this might affect the application of umask.. which i'm enabling by:
        ForceCommand internal-sftp -u 0007
    I was really hoping i'd be able to force this on the file-system level with acl or something similar

  • Sharing ITunes files across multiple windows user accounts

    How can my husband and I share our music files across two windows user accounts on the same computer.  As of now, when one of us buys new music, the other cant get it in their music library.  How do we get it to show up for both of us?

    follow this link to support article. http://support.apple.com/kb/HT1203

  • Lion administrator setting changed to read only for file sharing. Now hung machine

    I was trying to network my Mac with a WIndows 7 machine and tried to have my name in the file sharing read write instead of other users such as administrator   when I changed the administrator to read  only for file sharing rights and could not add my name as a file sharing user with read write permissions Really silly move
    I have performed a repair of disk permissions however still hung.
    Whats worse is that my time machine for the last three days has been disconnecting when backing up leaving a partially complete backup. Backup failed. I also left a apple support community message a few days ago to solve it.
    So its critical
    Timely HELP is needed.

    This same problem happened to me, all the sudden one day my mac decided to revert to the original standard root username and password which I obviously did not know. In order to change this:
    1) Activate single user mode on reboot as by pressing cmd + s as your computer starts up. Make sure you do it right away, and keep the keys pressed down.
    2) Where the cursor pops up, type exactly
    +/sbin/mount - uw/+
    3) When the next cursor pops up type exactly
    passwd
    4) Then you can type any password you want (now changing the root password to be what you want)
    Note you will not be able to see what you type, but the text is being recognized
    5)The computer asks for you to retype the password, retype it
    6) Type reboot
    Once the computer restarts you can navigate to system preferences>accounts> and then unlock the account (lock is located on the bottom left corner) using Username: root and the password you just set. Henceforth, you can appoint your account as the administrator. Hope it works!

  • How do I use VPN for file sharing?

    Hi folks, hope you can help.
    I need to find a method for file sharing between my company's two offices, which are not only in different countries but also use both PCs and Macs. I think setting up a VPN is the way forward.
    My file server is a Mac Mini running the standard client version of OS 10.5.4, with a static IP, 217.xxx.xxx.xxx. I need the PCs and Macs to access its resources. It is set up to share its files using FTP, AFP and SMB. It is running the application iVPN Server, which I understand is a GUI that makes the built-in OS X VPN Server function available to the client edition of OS X.
    I am currently overseas and can connect to the Mac Mini over VPN. The problem is that I cannot seem to access the Mac Mini's files - I don't know what to do having established the VPN connection. I was half-expecting it to show up in the Finder under Shared or something.
    The Mac Mini has a local IP of 10.0.1.20, but the VPN Server is issuing an IP to all clients in the range 192.168.2.200 and beyond. Is this where I'm going wrong?
    Should the Mac Mini VPN Server also connect to itself, using VPN, as a client?
    I'm really stuck, all help is very much appreciated. Thank you!

    Thanks for prompt reply Topher..
    I am familiar with the Connect to Server window, but I am not sure which IP I should be using. Assuming no VPN connection for the moment, and assuming I'm on a remote network, I can connect to the User's documents folder on the Mac Mini already by typing afp://[username:password]@[static WAN ip]/Documents
    However, I need to ensure that SMB shares work (I know they work when I'm on the local network). So I type smb://[username:password]@[static WAN ip]/Documents but this fails to connect to the User's Documents folder.
    To make the SMB shares work I think I have to connect using VPN. So I connect to the Mac Mini via VPN, and my laptop is issued a VPN IP of 192.168.2.200. Of course my laptop also has an IP from my local network. Do I need to rearrange my network order in System Preferences?
    So I'm now connected via VPN. However to view the Mac Mini's files, surely it also needs to have an IP issued by the VPN Server? But the Mac Mini is the VPN server. So should I go into its System Preferences and set up a VPN connection to itself?
    Now back on the laptop and I want to browse User's Documents folder on the Mac Mini using SMB. I go Connect to Server, and I guess I would type smb://[username:password]@[Mac Mini's VPN IP]/Documents
    Am I on the right track? Thanks again...

  • File Sharing with Multiple Users

    I wanted to set up file sharing on a Mac Mini for a group of Windows users. There are two things I wanted to do with this.
    1. Have a folder with a list of commonly used files and folders for the users to access.
    2. Push a backup of certain files that belong to individual users to the Mini for backup. I don't want one user to have access to another user's files on the Mac Mini.
    Is there a preferred method of setting something like this up? Do I create users as Sharing Only users? I'm used to Windows server shares, where I specify the access on a folder level basis. I'm not sure how to do this within OS X. Maybe I'm thinking about this all wrong. Any input would be appreciated.
    Thanks in advance.

    Each user with access to the Mac would have access to its public folder. That would work for one of your tasks.
    It would be no problem to set up a folder for each user on the Mac. Not so sure about the push part. They'd probably need to pull.
    Your main task will be to get the basic sharing going for the PCs. Fortunately, as things are todsy under Leopard and Snow Leopard, that's easier that the other way. I am hoping that the PCs all are running Vista or Win7. What are they running?

  • Frustrated with file sharing to windows

    Prior to Leopard, file sharing was SO easy it was one of the greatest features of owning a Mac at my Windows centric office. Now after installing Leopard, MONTHS of reading online forums and the discussions here has gotten me nowhere. The only success I've has has been with FTP.
    Can someone PLEASE help me or direct me to the proper tutorial of how to share files on my MacBook Pro with Windows machines? [I don't believe I just begged for help with my Mac!]
    What I have accomplished so far is enable sharing in the Sharing Pref Pane and I turned on SMB as everyone has suggested. My Windows machine can see my user folder and all the folders within it but I can not open any of those folders. If I change the access for Everyone to Read & Write then I can do what I'm trying to achieve. Obviously I don't want everyone on my network to have access.
    It would seem to me that I'm looking for a simple dialog window on the Windows machine to enter my user name and password but I don't see that. I can not find anyway to "LOG" in to the MacBook Pro.
    Why is it that I'm reading all this praise for Leopards new and improved file sharing features yet it seems like they've broken what had worked in the past?
    Now that I think about it, I think I was running SharePoint before so that was probably why I never had any issues before. That program unfortunately no longer works in Leopard.

    I'm a little confused now. I did as you suggested bulldog and created an account in the Sharing Pane with the same user name and password that I use on my Windows machine and gave it Read & Write Access.
    When I went to my Windows computer and attempted to navigate from Network Places to Workgroup, Workgroup was not there. I tried to reset my network connection and refresh the window but could never get Workgroup to come up.
    I then tried one of my previously mapped shares ("user" on Anthony's MBP) and got an error.
    I figured maybe that mapped share's IP got screwed up or something so I went to RUN and typed in my IP address of the Mac. 192.168.1.2/homefolder This actually prompted me for a user name and password! I entered the UN/PW that I had just created, the same one that I use to log in to my Windows machine, and got nothing. It tried to put PCNAME/ before my user name.
    Then I tried my UN/PW that I use on my Mac and that FINALLY worked. The confusing part is I KNOW that I've tried this many times before - it's always the FIRST thing that I try. I liked your idea Bulldog and thought that for sure it should work and I like how it limited access to certain folders for that user name.
    To add further to the confusion, I thought I'd give everything a second chance before I submit this post. I disconnected from the shared folder on my Windows computer to try and start over. It seems that now Workgroup is showing up. When I double click on that I see my Mac. When I double click on that I get a prompt for a user name and password. I tried both my Mac and Windows usernames and now NEITHER are working.
    I turn off File sharing to try to reset it on the Mac side and turn it back on. Workgroup is still present in Windows but when I double click it, it now stalled for 30 seconds and gives me a network path not found error. I repair my network connection in Windows, Workgroup goes away.
    I try RUN IP address again and it says that 192.168.1.2/homefolder is not available. I double check and verify that File Sharing is turned on and Read & Write is on for both Mac and Windows user names.
    I restart the Windows computer (incidentally a Macbook)
    No change
    I, again, turn OFF File Sharing - Turn it back on. Now I realize that when you restart file sharing you have to go back to Options and turn on SMB! Doh!
    Still no Workgroup but when I enter the IP address I get a prompt. I want to see if Workgroup shows up first though.
    I can't get Workgroup to show no matter what I do. I go back to enter my Mac's IP address/homefolder and try the Windows UN/PW and that still does not work. Only entering my Mac's UN/PW works at this point.
    For the moment, this will do for me. But it's still not correct from what I can tell. NOR IS IT EASY! Especially considering that what I have found to successfully work today is EXACTLY what I have ALWAYS used to access my Mac computers from a Windows computer.
    NOW that I'm connected (?), Workgroup shows up! I double clicked on it and it again prompted me for a username and password. I entered the same one that I used in the last step (Mac UN) and it successfully revealed all the mounted volumes on the Mac.
    This is still not solved because I can only get one username to connect remotely to my Mac. Thanks for the help though!

  • MacBook air not connecting to iMac for file sharing

    Hello, I have a 2012 MacBook Air running Mavericks.
    I am trying to connect (for file sharing) to an iMac also running Mavericks.
    File sharing is turned on on both computers.  File sharing used to work fine before the upgrade to Mavericks.
    Both computers are on the same network.  I can ping the iMac from the Macbook.  I see the iMac listed on the sidebar of my MacBook's Finder as a Shared drive.
    Both computers have iCloud turned on.
    However, when I click on the iMac in the Macbook's Filder sidebar, it shows up as "Connection Failed."  I click on "Connect As" and nothing happens--no pop up window, nothing.
    On the MacBook I am able to use Finder->Go->Connect to Server, enter my iMac's IP address and file sharing works (I can access the files).  But when I go to some other local folder and come back to the iMac server, again I cannot see the files.  Then I have again do Finder->Go->Connect to server, etc.
    (On a different MacBook Pro on the same network I had the same problem, but when I clicked on "Connect As" it asked me to choose a user id and password, and I was able to connect using my Apple ID.  However on the MacBook Air I am unable to click on "Connect As.")
    Any suggestions on how to fix this will be very much appreciated.
    Best,
    ADD in HK

    Sorry for the delayed update. This is issue is resolved by configuring my router to operate on Channel 11.
    Looks like my router could operate on Channels above 11 like 12, 13, etc, whereas Macbook Air could recognise only till Channel 11.
    Once the router was configured to use only Channel 11, my issue got resolved.

  • File Sharing - notifying secondary users that a file is already in use

    We are using a Lion server for file sharing. How can we set it up such that if one user has a file open, a secondary user opening the same file will be notified that the file is already in use (making it read-only)? We had multiple users opening the same file concurrently and making changes to it. Not a good scene and kind of flies in the face of using a file sharing system.
    I am not the server administrator, but trying to guide the person who is. Thanks for your help.

    Axehandler wrote:
    Is there a way to find out which program/service might be opening these files?
    Yes, use handle or process explorer from sysinternals. (see also).
    How is your labVIEW program structured? Could it be that your LabVIEW program itself holds on to the file from e.g. a previous file IO operation? Make sure references don't become invalid (e.g. via a "use default if unwired output tunnel) which would prevent the file from getting closed properly for example. Your program should open the file once at the start of the program and keep it open for the duration of the run. This way you should not have any intermittent problems accessing it.
    LabVIEW Champion . Do more with less code and in less time .

  • Forms Authentication Error: User '' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed

    I created a custom security extension following the steps listed in the Readme_Security Extension Sample. It works fine if I login as the user that is specified AdminConfiguration section of the rsreportserver.config file but if I
    log in as another user, I get this error: User '' does not have required permissions. Verify that sufficient permissions have been granted and Windows User Account Control (UAC) restrictions have been addressed.  I've added the user to both System Administrator
    and System User roles to try to get it to work but still no luck.
    Does anyone know how to fix this?
    Thanks.

    Hi MetronM,
    The issue is due to that user have no permission to access the report server. In report manager, Reporting Services includes predefined roles that we can assign to users and groups to provide immediate access to a report server. Each role defines a collection
    of related tasks.
    You can refer to the following steps to assign corresponding role to the user.
    Open report manager.
    Click “Folder Setting” button. 
    Click “New Role Assignment” icon.
    Type the user name and select the corresponding role.
    There is an article about Granting Permissions on a Native Mode Report Server, you can refer to it.
    http://technet.microsoft.com/en-us/library/ms156014.aspx
    Regards,
    Alisa Tang
    Alisa Tang
    TechNet Community Support

  • File sharing with multiple users on one Mac

    I have two Macs, both of which ca seen each other across the network. My question regards file sharing with multiple users on the same computer. When file sharing, are the files from all users available across the network, or just those of the user presently logged in? The issue is that I am trying to access files from a user who isn't currently logged in, but another user on that computer is. I need to get into that person's documents, but I don't see a way to navigate to their documents folder.

    Right, I got that. But the computer is in constant use by User A, while I need access to User B's files. I could need access at anytime, and it would be a pain to make User A log off and log in as User B everytime. I was just wondering if there is anyway to access User B's files in this situation, without logging User B in.

  • File Sharing between Windows PC and MacBook Pro using Internet Sharing

    I have a MacBook Pro and a Dell Latitude D820 running Windows XP SP2 and I want to connect both using any of these two options. I do not have a wireless router and I use Sprint 3G data card to access internet.
    1) I access the internet using a EVDO data card on my MAC and use Internet sharing to access the internet on my Dell laptop. How do I access the files on my PC from my MAC?
    2) I can have two EVDO data cards to access the MAC and PC independently. How can I setup file sharing between Windows laptop and MAC?

    Hi Dr. Poultry-
    This may be helpful: Mac OS: Connecting to the Internet and sharing files locally at the same time
    Luck-
    -DaddyPaycheck

Maybe you are looking for

  • Not connected to internet when using vpn

    Hi all - new to MACs and having a couple of problems ...... when I connect to internet using built in ethernet no problems .. when i connect with vpn(pptp) I gt te message connected to server but when i open safari and ty to connect to webpages i get

  • Network wise PR creation in CJ20N (PS)

    Hi all, I have one requirement regarding PR creation through CJ20N. In PS scenario, under one project there will be number of WBS elements and under each WBS element number of network will be there and under each Network there will be number of activ

  • How to use resourceBundle in Catalog Definition

    hi all, I am using wc11g, I need to use resourceBundle to display different title for different languages, according to the following doc: The name of the resource bundle to be used for obtaining translated attribute values, where <attribute.... isKe

  • Work Flow Software for Code

    Does anyone have any suggestions? I'm looking for a software product that would help regulate programmign work flow. For example: if we have several programmers working on the same application, we want a)everyone to have the same version of the appli

  • Upgrade Logic 7.0.1 to 7.2

    I'm trying to upgrade Logic 7.0.1 to 7.2. There used to be a nice cheap crossgrade that you could get for $49. Of course, I didn't have the money at the time. Now this crossgrade is no longer available, at least I can't find it anywhere! Here's an ar