Re: deny access to all but 1 folder



Denying access would be fine. All I want is the user only to have access to
one folder. I thought with 2003 that users had no access to any folder
unless specifically granted. I don't want user logging in and deleting or
modifying files and folders in drive c:.

Andy

"Vera Noest [MVP]" <vera.noest@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:Xns993CEC3E9CDCFveranoesthemutforsse@xxxxxxxxxxxxxxxx
You have to differentiate between "hiding" and "denying access".
These are 2 completely different things. Hiding is a purely
cosmetic feature, which doesn't provide any security (other than by
obscurity). Denying access with NTFS permissions doesn't hide the
folders, unless you use Access-Based Enumeration on shared folders.

You cannot deny access to the whole C: drive, since users must have
at least Read + Execute rights to most parts of the program files
and system folders.
And you cannot deny access to Documents and Settings either,
because it is their own profile, so they must have full control
there.
The default NTFS permissions on a Windows 2003 TS need no
modification.

But you can hide the C: drive completely, which means that it isn't
visible in most of the "Open file" dialog boxes in most
applications (but there are exceptions).

After hiding the C: drive, you can give your users access to the
\borland folder by assigning it a different drive letter. Put a
line in your TS-specific logon script with something like:

subst B: C:\program files\borland\

Then teach your users that the Borland files are on the B: drive.

_________________________________________________________
Vera Noest
MCSE, CCEA, Microsoft MVP - Terminal Server
TS troubleshooting: http://ts.veranoest.net
___ please respond in newsgroup, NOT by private email ___

"Andy Dyble" <andy.dyble@xxxxxxxxxxx> wrote on 26 maj 2007 in
microsoft.public.windows.terminal_services:

Dragos, I'll try and explain a bit better, I was a bit too
brief.

The user is existing.
My main objective is to deny access to all of drive C for a
user, except c:\program files\borland\
using NTFS security.

Thanks

Andy

"Dragos CAMARA" <dragos_c@xxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:B4073FBF-0271-4560-B2C8-1D90A6BE00E3@xxxxxxxxxxxxxxxx
hi,
for existing users it is possible, but for the user who will
login for the first time?Another solution is to redirect the my
documents folder. --
Dragos CAMARA
MCSA Windows 2003 server


"Andy Dyble" wrote:

"Dragos CAMARA" <dragos_c@xxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:A86AB887-B62E-4628-8A31-52427D3C480E@xxxxxxxxxxxxxxxx
hi,
create mandatory profiles for users who use TS.
--
Dragos CAMARA
MCSA Windows 2003 server


"Andy Dyble" wrote:

Hi
On our TS, we are tryong to deny access to the whole of
drive C, except
one
folder, which requires all users to have list, read,
execute rights, and
one
or more extra folder for each user (not home though), that
require modify
as
well.

We tried applying security to drice C:, this looked like it
was working
because users were getting access denied, but then found
they can open My
docouments and any other folder inside the drive.

TS= 2003 Standard, member server to 2003 Ad server.

Thanks

Andy Dyble


Cheers Dragos, but shouldn't this be possible using NTFS
permissions ?

ANdy


.



Relevant Pages

  • Re: Email enable doc lib
    ... navigate to the public folder and send some posts with attachments to the ... Microsoft CSS Online Newsgroup Support ... I have disabled forms base Athentication from the default V.Smtp server ...
    (microsoft.public.windows.server.sbs)
  • Re: deny access to all but 1 folder
    ... And you can *not* deny access to C: (with NTFS), ... MCSE, CCEA, Microsoft MVP - Terminal Server ... no access to any folder unless specifically granted. ...
    (microsoft.public.windows.terminal_services)
  • Re: Newbie with a smallbiz2000 installation, check my config?
    ... > Windows creates a profile path under Documents & Settings. ... > a folder with that name already exists (maybe a local user with the ... > server, open the properties for this folder, and ensure that you have ... > you redirect key folders from a user's profile to a location on your ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Network shares cannot connect
    ... User Name: SERVER$ ... Regarding the shares accessing problem, I suggest you try following steps ... let's focus on the Users Shared Folder first. ... To check this permission, please click the Advanced button, select ...
    (microsoft.public.windows.server.sbs)
  • Re: Disappearing disk space?
    ... I switched off the AV scanning completely last night and the ... Windows Server 2003, Windows 2000, or Windows XP ... %systemroot%\Sysvol folder ... KB309422 - Guidelines for choosing antivirus software to run on the ...
    (microsoft.public.windows.server.sbs)

Loading