Re: Changing default Security on Home Directories

From: lforbes (UseLinkToEmail_at_WindowsForumz.com)
Date: 03/01/05


Date: 28 Feb 2005 23:09:15 -0500


"EvanGordey" wrote:
> I am trying to integrate some macs into our windows 2003
> server environment.
> The problem I have is with the security on users home
> directories. I work in
> a school, so the group "teachers" is for teachers and the
> group "students" is
> for students.
> The way I currently have it set up is as follows:
> I have a share set up on the server for students called
> "StudentDirectory"
> and the Active Directory template for making new students puts
> their home
> directories in that share. The way security is set up on this
> share is that
> Administrators and the Teachers group can administer all
> folders underneath
> it using inheritance, which works awesome in a straight
> windows environment.
> The students group doesnt have read access on the share
> itself, just on their
> own directories created underneath it.
>
> Now the problem. The way the macs seem to work is that when
> they
> authenticate into active directory, they mount shares. As I
> have it only the
> parent folder "StudentDirectory" is shared, and if you log
> into a student
> account on the macs you cant mount your home directory unless
> you have read
> access to the share. I cant give them read access to the share
> as it stands,
> because then they would be able to read into all the other
> students home
> diredtories because of inheritance.
>
> I am wondering if their is a way in AD to set up thorugh
> policy or something
> the default set of permissions and to also disable inheritance
> on a users
> home directory when created. This would allow me to give the
> students group
> read access to the "StudentDirecory" share without being able
> to browse into
> other students home folders
>
> If I am using really bad grammar, I'm sorry. I am trying my
> best to explain
> the problem I am having so that you guys will understand.
>
> Thanks

Hi,

The tip is to give them "Read Access" in the Upper Folder
permissions and then go into Advanced and change FROM "This folder,
subfolders and files" TO "This Folder only". This gives them read
access to the upper folder but is NOT inherited to subfolders.
Therefore they can see the list of users folders and the names, but
can’t enter into them.

This is the way the home folders should be setup with Window 2003. As
Windows 2003 sets up users folders with inheritance whereas Windows
2000 didn’t.

Cheers,

Lara

-- 
Posted using the http://www.windowsforumz.com interface, at author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.windowsforumz.com/Group-Policy-Changing-default-Security-Home-Directories-ftopict271438.html
Visit Topic URL to contact author (reg. req'd).  Report abuse: http://www.windowsforumz.com/eform.php?p=856265


Relevant Pages

  • Index of files in restricted folders
    ... I am the system administrator of a high school. ... based active directory with roaming profiles for the students. ... The students are ripping CD's using windows media ... folders on the server and delete all music files. ...
    (microsoft.public.windows.server.security)
  • Re: permissions question
    ... >I have a network set up in a computer lab in a school. ... >their work in the same folders in a common folder on each PC. ... same account, with identical password, on each of the students computers. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Changing default Security on Home Directories
    ... > I have a share set up on the server for students called ... > diredtories because of inheritance. ... > other students home folders ... Windows 2003 sets up users folders with inheritance whereas Windows ...
    (microsoft.public.win2000.group_policy)
  • Re: file sharing from 98 to XP Pro
    ... > I'm trying to set it up so I can use an old 98 PC as a file server. ... > I've created folders for all of my students on the 98 PC's, ... If you want to stick with Windows, ...
    (microsoft.public.windowsxp.general)
  • Re: Share point suggestions
    ... At the Class Folders level will I be adding the teacher and student groups? ... Also put Mr. Smith in the Smith group. ... At the Class Folders level give Students and Teachers List Folder Contents ...
    (microsoft.public.windows.server.active_directory)