Share permissions issue - users reporting files readonly

I have setup a share and the users need to have access to read,modify, write, delete on the files/folders in the new share. The users. For this:
1. I added the user AD group to the Share Permissions and set 'Change' for the permissions. I noticed that there was already a group called Everyone here and had 'READ' permissions. I did not make any changes to this Everyone group.
2. I added the user AD group to the NTFS Permissions and set 'Modify, Read&Execute, Read, Write' permissions. 
It seems the users are seeing the files as 'read only'. They can view and open, but are not able to edit the file. What might be the issue?
Regards

Hi,
I have added share and NTFS permissions the same as yours on a shared folder and I can eide files within the shared folder. Please check the NTFS permissions of the files in the shared folder to see it the NTFS permissions are inherited to the chiled files
from the parent folder.
HOW TO: Control NTFS Permissions Inheritance in Windows
http://support.microsoft.com/kb/313398
Best Regards,
Mandy 
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

Similar Messages

  • Permissions issues on folder/file created by impersonation workflow

    Hi,
    I have used impersonation to create a new
    folder, copy a Word
    template inside it, and rename the file. Content
    management is on but checkin/out is off. When the doc is printed or saved, it should prompt for a label and barcode. The workflow works fine and when I test it the barcode/label works, but when anyone aside else (aside from our admin) tries to
    edit the document it downloads to
    their desktop and the label/barcode prompt doesn't happen. Also no refresh green arrow icon over the Save command in Word. We are all members of the same Owners group for that library (inherited from parent doc centre site: Full Control, Limited Access) although
    I am also a Designer and User.
    Any ideas?
    Should I start experimenting with unique permissions until
    I hit on the right set? There's only 1-3 people who need to be able to edit the documents. I'm not a programmer.
    Thanks.

    Hi,
    I have used impersonation to create a new
    folder, copy a Word
    template inside it, and rename the file. Content
    management is on but checkin/out is off. When the doc is printed or saved, it should prompt for a label and barcode. The workflow works fine and when I test it the barcode/label works, but when anyone aside else (aside from our admin) tries to
    edit the document it downloads to
    their desktop and the label/barcode prompt doesn't happen. Also no refresh green arrow icon over the Save command in Word. We are all members of the same Owners group for that library (inherited from parent doc centre site: Full Control, Limited Access) although
    I am also a Designer and User.
    Any ideas?
    Should I start experimenting with unique permissions until
    I hit on the right set? There's only 1-3 people who need to be able to edit the documents. I'm not a programmer.
    Thanks.

  • How to set NTFS and share permissions for Users share for home directories in Server 2012

    I have a new Server 2012 server, and I want to set up a Users share, that will contain subfolders of each user's username and contain their home directory.  But what do I set the share and NTFS permissions as on the root level, lets call the folder
    Users? Is the following older article the correct permissions I need?
    https://support.microsoft.com/kb/274443

    Hi RJO22,
    You can choose configure the Folder Redirection, Folder Redirection enables you to redirect the location of specific folders within user profiles to a new location, such as
    a shared network location. Folder redirection is used in the process of administering user profiles and roaming user profiles. You can configure Folder Redirection using the Group Policy Management Console to redirect specific user profile folders, as well
    as edit Folder Redirection policy settings.
    The related KB:
    Folder Redirection Overview
    http://technet.microsoft.com/en-us/library/cc732275.aspx
    Specify the Location of Folders in a User Profile
    http://technet.microsoft.com/en-us/library/cc771969.aspx
    I’m glad to be of help to you!
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How do I migrate from one user to another to resolve sleep/permissions issues?

    My MacBook Pro's been having several issues, mainly with waking from sleep. I've tried Repairing Permissions, Repair Disk, running tools like OnyX and Drive Genius, but they can't find any issues. I checked the Console log, and there was some sort of denial from displaying the login window after I woke up from sleep.
    Initially I thought this had to do with some of my peripherals being plugged in when I already had the lid closed; the Mac would wake up, not realize the lid was closed, and never go back to sleep. Nothing--keyboard or trackpad touches--would wake the machine up. I'd have to hard reset by holding the Power button on.
    I had an Apple Genius suggest that I create a new user and test it out with the (same) default sleep settings as the buggy user account. It wakes up from sleep lightning fast, and has thus far never had any issues.
    I'm leaning toward sticking with this new user and migrating over my things bit by bit, to try and avoid potential permissions issues. But since I don't know where the source of this sleep problem lies, how should I go about it?
    I've read through Pondini's Transfer Guide here http://pondini.org/OSX/Transfer.html, but I'm just wondering where people would start, knowing that the machine has had permissions issues with some files. (The permissions issues, btw, I believe were caused by a mangled Time Machine restore. I replaced my internal HD with another one, but the Time Machine/Migration Assistant restore wasn't complete. I did it a second time from within the user account that got created, then tried to delete the malformed one and rename the complete one, but that's when the issues started.)

    I wasn't intending to move the entire home folder, rather, moving things like what's inside my Documents folder in chunks.
    From what I read, tracking down the origin of sleep/wake problems on a computer is notoriously hard, especially if Disk Utility and similar tools don't give any clues during Repair Disk or Repair Permissions. Creating the new user seemed to help, but I don't know why that alone would "fix" anything, so I haven't moved any files as of yet nor done anything with the new user account.
    Trying to move the things from my Library folder to my desktop also seems a bit risky; it's hidden in Lion and Mountain Lion because a lot of system files are there, right? Wouldn't moving them cause problems, not just help me find what file/folder (if any) could be the culprit?

  • Photoshop creates wonky file permissions after  different user modifies file and saves over

    We have a fileserver sharing out files to Windows clients using samba service on Mac OSX Server 10.6.5.
    We have weird permissions issue with psd files in Photoshop CS5 64 bit.
    A user (userx) belonging to the group wheel creates a file called version1.psd
    POSIX
    ACL
    user    Read & Write
    wheel  Read & Write
    others Read & Write
    A different user (usery) opens version1.psd, makes some modifications and save it out as version2.psd
    POSIX
    ACL
    usery  Read & Write
    wheel  Read & Write
    others Read & Write
    Now userx opens version2.psd and makes modification and saves the current file. Userx can nol onger access the file he just saved.
    POSIX
    usery Custom
    ACL
    userx  No Access
    wheel  Read & Write
    others Read & Write
    This led me to test modifying original file (version1.psd) and save. It does the same thing.
    Don't understand why it has this behaviour. Is this some kind of bug with photoshop as when we do modifications outside of Photoshop, permissions are always fine? Thanks ahead for any help.

    We have solved our issue.
    After running Adobe updates on machine that uses CS6 and then re-starting that machine, our issue seems to have disappeared.
    Hope this helps others.
    Best of luck.

  • Time Machine Permissions Issue

    Hello,
    Here's the deal:
    I have accidentely deleted some files from my computer's iChats Folder. I had backed-up my computer prior on Time Machine. I went into Time Machine and found the folder and pressed restore yet it then gives me the error message, "The file XYZ cannot be moved because you don't have access to it." I realize that the problem is a permissions issue with the files. What I don't understand is why it says this if its been backed-up on the same computer all the time. In addition, I can move ANY ONE file from the folders at a time with no problems but when I try to move the whole folder, it doesn't work. PLEASE HELP.
    Thanks

    anyone???

  • BIDS - report file permissions issue on master, yet im a sysadmin when running the RDL from SSMS

    Im building a report file and when I preview the report, it fails because my account cant access the master database.
    My dataset is just calling xp_readerrorlog, which is in master.
    I can call it just fine in a query window, but not from BIDS, using a connection with windows security.
    I can however, preview the dataset ok, but when I open the RDL file from SSMS under custom reports, I get an login error.
    However, if I preview the report...it fails and says the login failed, login failed for user mydomain\myuser ....

    Hi,
    It seems a permissions related issue, try the following methods to troubleshoot the issue:
    1. Use this form of giving the user exec rights on extended stored procedure.
    create user usename for login login
    go
    grant exec on xp_readerrorlog to username
    Refer to:
    http://social.msdn.microsoft.com/Forums/sqlserver/en-US/ffd3a32b-7e17-4f15-9fb7-fa744611ac7e/minimum-persssion-required-to-execute-spreaderrorlog-system-stored-procedure
    2. Run BIDS as administrator and see how it works.
    3. Also, check the SQL event log (SQL Server Management Studio > Management > SQL Server Logs) and post the full error message for the failed login.
    Thanks.
    Tracy Cai
    TechNet Community Support

  • Sharing files between user accounts without permissions issues

    I have two user accounts on my iMac and need to make files available to both accounts, back and forth, without having to worry about permissions issues. Files need to be read and edited from both accounts.  I posted previously about this and was told to place the files in Users/Shared.  I've done this but it hasn't accomplished what I need.
    I created a document in one account and saved it to Users/Shared, but when I opened the document from the other account and tried to edit it, I was told that I didn't have permission to edit and that I needed to duplicate the file.  How can I avoid having to set permissions for files that I need to edit from both user accounts?

    Or not.
    I butt up against this lunacy frquently.
    I have just created a file saved to my external NAS - no problem - tried to save my edits - now don't have permission to do so.  Again - checked - custom access - again.  Ridiculous.
    Why can Apple not sort out this fundamental problem - if I create a file and put it on my network where I WANT IT - the OS should not then prevent me from accessing it.
    I spend hours, regularly, trying to sort this out.  Apple OS is a joke.
    And to be kept being told - do this, do that, use terminal, reset passwords is ridiculous.
    Sorry for the rant.
    But this is the limit.
    Mike

  • Can't Customize, Change Settings, or Move Files -- Permissions Issue?

    Hey all:
    Just got a new MBP w/ 10.5.2. Successfully migrated most of my user settings and applications from the old Tiger HDD (old laptop died a horrible death).
    The problem is that aside from everything appearing to be the same, I'm finding that I don't have the access to do a whole lot with my own files. Several different problems that "seem" like they're stemming from the same accessiblity/permissions issue include:
    Intermittent trouble downloading files with Firefox's default download tool.
    Complete inability to change desktop background.
    Programs fail to remember setting changes after quit and re-launch.
    System Preferences do not remember changes to settings.
    Certain files can not be moved, renamed, opened, or deleted w/o admin authorization, or in some cases, at all.
    The problems started after I migrated the old system over after having an interim user account running for a few days prior. After migrating, I attempted to reconcile the two together and that's when things got hairy.
    In the past couple days, I have tried:
    1.) Archive and Install (preserving User settings - now down to just one admin).
    2.) Changing permissions to system read/write, admin read/write, everyone read only for the entire /User directory, applied to all enclosed items.
    3.) Repairing Permissions (which took about 10 minutes!)
    I'm at the end of my rope here. I'm stuck with my OS acting the way it wants to, which is the exact way it was after being archived and reinstalled, no matter what changes I try to apply in the Finder, Preferences, or in any programs.
    I'm thinking maybe a clean install and then migrating over the backup I just made on my external HD will get me my stuff without whatever troublesome thing is freezing me out, but I'm not really sure, and I don't really understand much about command lines in Terminal.
    Does anyone have any ideas? Many thanks.

    Oddly enough I just had a spastic moment with a mouse click and put my Drop Box in the Trash (I keep the Delete thing in my window toolbar, which is handy, but can lead to accidents)... Since I was playing with it I noticed its absence immediately. Realized what I had done after a moment's reflection, and put it back. Which just goes to confirm something I ALWAYS do before I empty the Trash: open it and see what's in there first, then click empty.
    As to whether removing ACLs is for advanced users only: well, up until Leopard that's the way it always was, there were, until now, NO ACLs on the users folders. So should everyone have been an advanced user until now? Did you ever delete a folder in Jaquar or Panther or Tiger and empty your Trash without checking? Indeed, if you use Time Machine, available in Leopard but not before, you are already protected from such goofs, since you can recover things accidently deleted using Time Machine, so actually you are in better shape with Leopard than ever before, WITHOUT the ACLs if you use Time Machine. Until Leopard there was neither belt nor suspenders to automatically protect you from losing data. Leopard supplies both.
    The situation reminds me of the continuing debate about virus protection on the Mac. Personally, I have seen various anti-virus programs cause all sorts of problems, and it has yet to protect any Mac system from anything (since as yet there are no Mac system viruses). Anti-virus software may have saved some users of Microsoft Office who share files with Windows users from getting a macro virus in their Word docs, and it might have kept a Mac user from passing on some email virus to some Windows users by forwarding stuff from the Internet. But still.... if you don't use MS Office or forward email junk, you get no benefit and may get some problems.
    Same seems to me to be true of ACLs: it is possible to get a benefit (you can't accidently toss your Movies folder and lose data, assuming you mindlessly empty your Trash and don't have a backup), but an awful lot of people are having an awful lot of problems.
    Francine
    Francine
    Schwieder

  • Mac user locks files for Windows users on NFS shares

    Hi Everyone,
    We run a mostly Windows environment here at my school and have two AD servers which also do our file shares for AD users. Every user has a network drive mapped to L on Windows, and this is mounted on the dock of our Mac users (all Macs are bound to the AD for auth and the OD for management). We also have shared folders for different groups of people, such as admissions or art (where the issue is). Most of these divisions are only Windows, so file sharing isn't and issue - but this is not the case in our Art department.
    We have a shared folder (T on Windows) setup for users of the Art department with mostly Office docs in it. Windows users can write to the share just fine, just as the Mac users can. The issue comes up once a Mac user edits and saves the file (all to the share) - Windows users are now locked out of the file because the permissions are reset. What can we do to fix this issue? It's obnoxious having to go and reset the permissions after every edit from a Mac user.
    Thanks,
    -MRCUR

    We also have that same problem. We don't actually solved the issue but we what we do did is just unlock the files once and even they are edited or opened in windows or mac, it does not lock the file. We use windows pc and connect to the drives and just simply right clicking the file then properties a button will show in the properties window saying "unlock". After we did that, those files was never locked out again.

  • Reporting Services Point - possibly permissions issue

    I'm having a really hard time configuring a working reporting services point in my test SCCM 2012 R2 environment and was hoping someone might be able to help me work out what's gone wrong.
    My servers are WS2008 R2.  SQL Server 2008 R2 is installed on the primary site server and holds the site database.  I installed SSRS onto a separate site server and added it as a reporting services point.  This worked, and I see the list of
    reports in the SCCM admin console.  However, when I try to run a report - either from the console or via web browser - I get this message:
    The default value expression for the report parameter 'usertokensids' contains an error.  There are no logon servers available to service the logon request. (rsRuntimeErrorInExpression)
       at Microsoft.Reporting.WinForms.ServerReportSoapProxy.OnSoapException(SoapException e)
       at Microsoft.Reporting.WinForms.Internal.Soap.ReportingServices2005.Execution.RSExecutionConnection.ProxyMethodInvocation.Execute[TReturn](RSExecutionConnection connection, ProxyMethod`1 initialMethod, ProxyMethod`1 retryMethod)
       at Microsoft.Reporting.WinForms.Internal.Soap.ReportingServices2005.Execution.RSExecutionConnection.LoadReport(String Report, String HistoryID)
       at Microsoft.Reporting.WinForms.ServerReport.EnsureExecutionSession()
       at Microsoft.Reporting.WinForms.ServerReport.SetParameters(IEnumerable`1 parameters)
       at Microsoft.ConfigurationManagement.AdminConsole.SrsReporting.ReportViewerWindowsForms.SetParameterValues_DoWork(Object sender, DoWorkEventArgs e)
    SMSAdminUI.log shows this message:
    [25, PID:3096][06/12/2014 11:24:05] :[fqdnofprimaryserver] : The request failed with HTTP status 503: Server Error.
    Now, the reason I think this is a permissions issue is because srsrp.log on the Reporting Point server shows this:
    (!) Error retrieving folders - [Login failed for user 'domain\reportingservercomputername$'.].
    (I've removed the actual name here, obviously.)
    I'm really puzzled about what's going on here, what is trying to authenticate with the SSRS server's machine credentials, and what for.  Looking in SQL Server Management Studio on the primary site server which hosts the SQL database, I can see that
    the account has a login listed and it has its default schema listed as DBO.  On the SSRS server, in Reporting Services Configuration Manager, the Report Server Service Account is set to a dedicated domain user account.  The Current Report Server
    Database Credential is set to my own Windows login using Current User - Integrated Security - I can't seem to get it to accept the dedicated user account.
    Can anyone help me figure out what's gone wrong and how I fix it, please?  I'm by no means a SQL person, and I'm at my wit's end with this!
    Thanks,
    M

    The plot thickens.
    The SSRS server has these:
    "The report server has detected a possible denial of service attack. The report server is dropping requests for service from the IP address 192.168.113.163" (this is the IP address of the primary site system, which hosts the SQL database)
    and then
    "Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database"
    The primary site system, meanwhile, has got thousands of these:
    "Login failed for user 'DOMAIN\SSRSSERVERNAME$'. Reason: Token-based server access validation failed with an infrastructure error. Check for previous errors. [CLIENT: 192.168.113.164]" (that's the IP of the SSRS server)
    The Windows firewall is off for both systems.  They're on an isolated test network.  I still don't understand where the setting is that tells it to make SQL queries using the SSRS server's machine account, rather than the dedicated service account
    I created.
    Any more ideas?  Thanks for your help so far - I really appreciate it!

  • Content Tracker Reports Query file modification issue - Custom Report

    Hi All,
    I was trying to generate a custom report using Content Tracker. I was successful in doing so. However, I found that sometimes it does not pick up the updated query file of Content Tracker reports.
    I made a change in my query:
    from SELECT * FROM Users to
    SELECT dname FROM Users
    the change is written on the file but when i generated the report from C.T. UI, it's still showing me the old results having all the columns. Tried bouncing the server as well, but no use.
    I also added a new query 24 hrs back (as SELECT count(*) As UsersNum FROM Users), it's still not recognizing it and giving error as Failure of server APACHE bridge: No backend server available for
    connection: timed out after 10 seconds or idempotent set to OFF;
    and the log says,
    Unable to execute service SCT_GET_DOCUMENT_INFO_ADMIN and function sctExecuteQuery.
    Unable to create the result set for query '(null)'. SQL statement to execute cannot be empty or null
    What could be the resolution of this issue?
    I am using UCM 11g + SSXA.

    Server bounce.
    Issue is not file update but some other issue, ongoing in another thread by Me.

  • Error creating custom reports. Permissions issue with custom reports

    I am having permission issues with reports. I am building a new Configuration Manager  2012 infrastructure and I have configured the Site server on Server1 and the DB is on Server2. Server2 also hosts the Reporting Point and SSRS roles/features. If
    I look in Monitoring at the Site Status and Component Status are all green no issues with the setup.
    Running SQL 2008 SP2 (no CUs). I have a service account that I used to install Configuration Manager and SQL. This service account is running the SQL service on Server2 and i am using the same account as the Reporting Services Point Account.
    I log into the SCCM console with a different user account, lets call it Admin1. This account is a member of the Full Administrator role. I can run any built in report.
    When I open the SSRS website and try to create a custom report I connect the DataSource using Windows Authentication. So the Datasource is connecting using the logged in users account. In this case Admin1. I test the connection and it connects fine.
    I test this query. (Select * from v_R_System) I only have about 10 workstations discovered so the report shouldn’t be very big. I get an error “The Select permission was denied on the object ‘v_R_System’, Database ‘CM_XXX’, schema ‘dbo’. (Microsoft sql server,
    Error: 229)”
    I have fixed the SELECT permission error by going into the database (using SQL Management studio) and granting Admin1 Select rights to the Configuration Manager database. I can now run the above query and make custom reports.
    My 2<sup>nd</sup> problem is that other members of the Full Administrator role cannot run these custom reports unless I go into the database and grant them the SELECT permission.
    Question:
    Should I have to manually go into the database to add SELECT permissions(i could use a group)? shouldnt Configuration Manager take care of this for me?
    Maybe the built in reports use the SQL service account rights and the custom ones do not? Am I doing something wrong with the Datasource when I create these custom reports?
    What is the correct process for creating custom reports?

    I think i am getting closer to a solution. After the Custom report is created. i can go back into the report. Delete the DataSource. Then browse for a dataSource. there is a datasource located in http://server2/reportserver/ConfigMgr_XXX/
    That datasource is used by all builtin reports. if you view the properties on the Credentials tab it is set to "do not use credentials" and the option is greyed out / cannot be changed.
    it looks like i still need the SELECT permissions on the database to create the report initially but at least i have solved the problem with viewing these reports.
    Can anyone confirm that what i did is correct?

  • Permissions for website directories/files & Share Points for managing files

    Hello.
    I'm wondering if anyone could lend some advice in how to best set up permissions, both POSIX and ACLs, for the following setup?
    #1 - Permissions for directories and files for hosting a website (via OS X 10.5 "Web" GUI). Basically, I'm curious as to what people suggest for the basic files for the directory (and sub-directories and files) that go into the backend (html, images, etc.) of a website? I'm going to be being files over from another machine, so I may need to propagate these permissions once they've been moved over?
    #2 - Permissions (ACL) for allowing users to access these directories and files for editing, etc. via client Macs on our LAN (this server is going to be a development web server for initial building/testing).
    Any advice would be much appreciated!
    Thanks,
    Kristin.

    Hi Kristin,
    The "other" or "everyone" group should not have "write" permissions to any files under your website document root folder. The Apache web server runs as user "www" ... "www" is usually in the "everyone" group, thus allowing read-only access to the website.
    You can set up the owner of your files to an admin account. Perhaps set up a group with write permissions to the file shares where your website files are.
    You must first analyze who should have access to what, base your groups on that ...
    Ted

  • Add a DFS file share path in User Profile disk in RDS 2012.

    I'm trying to add dfs file share path  in User profile disks .I get a error message "Access denied"
    Is it possible to add a dfs file share path ?

    Hi,
    It seems we cannot use a DFS file share path here.
    I found a similar thread:
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/d8eafa8f-8999-443f-a2d7-8e6dfa3a2908/user-profile-disk-store-on-a-dfs-?forum=winserverTS
    In reply it mentioned "the share needs to be provided from a 2012 server directly as it needs to manage the permissions and share permissions directly".
    As you tested you get an access denied error when trying to use a DFS share. 
    If you have any feedback on our support, please send to [email protected]

Maybe you are looking for

  • Service order type creation

    Hi, I want to create a service order type. We dont have any requirement to create any service notification for it. Could any one please tell me is it necessary to create a service notification before a service order. Thanks and Regards

  • How to get the primarykey columns of the table in SAP BI Java SDK

    Hi, I'm new to sap BI Java SDK. I'm not getting how to get the primarykey columns, using BI JDBC Connector (for relational data sources). If anybody knows, please let me know. its very very urgent task to be done in my project. In the below following

  • Received this email is it valid or spam

    Dear Valued Verizon Customer, To further improve security and your online experience, Verizon has modified the way Verizon.net email is handled when sent or received through an email application (such as Outlook Express®, MS Outlook, Windows Live Mai

  • How can I scroll messages and folders in Mail with Maverick? It's unacceptable for Apple

    How can I scroll messages and folders in Mail with Maverick? It's unacceptable for Apple to have allowed this to happen

  • Dreamweaver 10.0 Build 4117 crashes

    Dreamweaver 10.0 Build 4117 crashes every time when starting up DW. With other account it starts without problems. I did a re-install, repaired privileges, deleted the preferences-file etc. No result. (What other files can i delete to resolve this st