Re: How to copy files with permissions plus the users from a stand alone server to another?



On Sat, 25 Apr 2009 12:31:30 -0700, Tony Barken <tonybarken@xxxxxxxxxxxxxxx>
wrote:

On Sat, 25 Apr 2009 10:21:52 -0400, "Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Tony Barken <tonybarken@xxxxxxxxxxxxxxx> wrote:
I have a stand alone Windows 2000 with tens of users. The machine has
folders with NTFS permissions beloning to the users. I need to copy
these files with their permissions and recreate the users on a stand
alone Windows 2003 server.

What's the best way to achive this? My idea was to use addusers.exe
from the resource kit to export the users to a file and recreate them
on the other machine. Then use a tool like Robocopy or Xcopy or
Acronis's TrueImage to copy the files to the other machine.
Would that work?
Wouldn't the SID values on the files be different and the ACL
permissions wouldn't work?

Any better ideas?

There's a commercial product called SecureCopy from ScriptLogic.com
which seems to do the job but its cost is beyond my budget.

Tony Barken


You could look into ADMT - and NTBackup can back up and restore permissions.
I'm not sure this would work, though. Why not test and find out?

BTW, this is an excellent demonstration of why it's so much better to use a
domain model. ;-)


I downloaded ADMT 3.1 and ran it on an XP just to check it out and it
said it wasn't a valid Win32 app. My two machines are stand alone and
are not part of a domain. So are you sure this tool will work. Active
Directroy implies machines connected using Active Directory.

I have a simple set up. Involving a domain means I need a domain
controller and this will compliate matters.
I think you are wrong. Having a domain will simplify matters a lot. Unless you
have just one or two users. I believe MS say the domain is easier if there are
10 or more users. Personally I think it is better if there are more than 2 or 3
users. If you already have a server then a Domain does not cost you any money.

For your problem though look at SUBINACL, it's about as friendly to use an a
alligator but does have the functionality to change ACLs from one SID to another
although I have never used it for that only to change the ownership or files.



Tony Barken
--
Dave Mills
There are 10 types of people, those that understand binary and those that don't.
.



Relevant Pages

  • Re: Cannot write to shared folder on W2K8 server
    ... After reading your latest post and Meinolf about how you cannot recreate my issues led me to try to recreate it myself. ... I created a new folder and share on C: and can write to it from my desktop. ... Which I still don't understand why it doesn't work especially if I had reapplied the share permissions and NTFS security. ... If that was the case, maybe removing the share and NTFS permissions, except for administrator, and then reapply the NTFS permissions, then the Share. ...
    (microsoft.public.windows.server.general)
  • Re: How to copy files with permissions plus the users from a stand alone server to another?
    ... folders with NTFS permissions beloning to the users. ... alone Windows 2003 server. ... from the resource kit to export the users to a file and recreate them ... Directroy implies machines connected using Active Directory. ...
    (microsoft.public.windows.server.general)
  • Re: How to copy files with permissions plus the users from a stand alone server to another?
    ... folders with NTFS permissions beloning to the users. ... from the resource kit to export the users to a file and recreate them ... Directroy implies machines connected using Active Directory. ... alligator but does have the functionality to change ACLs from one SID to another ...
    (microsoft.public.windows.server.general)
  • Re: permissions resetting on a View
    ... you run the sp_refreshview it appears to keep the permissions on a view. ... If you really want to create or alter a view via a stored procedure you can ... "Terrell Miller" wrote in message ... > delete the view and recreate it? ...
    (microsoft.public.sqlserver.server)
  • Re: permissions for group policy??
    ... Even if you recreate the same name etc. the SID is different from the SID that is used on your profiles. ... So you have to set in every user profile folder the rights by hand for the recreated username with Full control as a minimum. ... By "re-creating" I had to recreate the user names, add permissions to ... administrators group tries to logon with their roaming profile. ...
    (microsoft.public.windows.group_policy)