Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Deny Delete on Folder Not Working?

Reply
Thread Tools Display Modes

Re: Deny Delete on Folder Not Working?

 
 
Anthony [MVP]
Guest
Posts: n/a

 
      08-01-2009
Ben,
It does work so I suggest you experiment a bit on a test folder.
Try giving users Read and Write but not Modify and see what you get.
Anthony,
http://www.airdesk.com


"Ben" <> wrote in message
news:73c17835-f218-49f3-a5d9-...
> Hi,
>
> I have a client who had an issue this morning where someone had
> deleted a large volume of folders on a server. Luckily we were able to
> restore the deleted files & folders. But we now want to block users
> from deleting folders.
>
> So the folder D:\Data is shared out as \\server\data, share
> permissions are set to 'Everyone' has 'Change + Read', and the NTFS
> permissions are set so currently Domain Admins have full control, and
> Domain Users have modify. Now I want to add the permisson 'Deny Delete
> Subfolders & Files' & 'Deny Delete'. So I've added this permission for
> 'Domain Users' under 'Security tab > Advanced' > 'Permissions' and
> also enabled auditing for success/failure of delete. However when I
> access the folder across the network via a test user who is a member
> of 'Domain Users', I can still delete the folder. The audit log shows
> that Delete was successful for test.user.
>
> I have tried adding the Deny permission for 'Domain Users', the built
> in group 'Users' and the group 'Everyone'. But no matter what option I
> use, I can still delete the folder.
>
> I'm running Windows 2003 R2 Standard SP2 in 2003 domain/forest mode,
> and Windows XP clients.
>
> Can anyone suggest why the Deny permission isn't working?
>
> Thanks
>
> Ben


 
Reply With Quote
 
 
 
 
Al Dunbar
Guest
Posts: n/a

 
      08-01-2009
Using DENY permissions can be tricky. I'd suggest to the OP to create a test
group to experiment on. If, for example, your domain admins are also members
of the domain, denying some right to domain users will affect the access of
the domain admins as well.

There might be other ways to achieve what the OP is after without resorting
to deny privileges.


/Al


"Anthony [MVP]" <> wrote in message
news:AA66F731-310C-4513-A450-...
> Ben,
> It does work so I suggest you experiment a bit on a test folder.
> Try giving users Read and Write but not Modify and see what you get.
> Anthony,
> http://www.airdesk.com
>
>
> "Ben" <> wrote in message
> news:73c17835-f218-49f3-a5d9-...
>> Hi,
>>
>> I have a client who had an issue this morning where someone had
>> deleted a large volume of folders on a server. Luckily we were able to
>> restore the deleted files & folders. But we now want to block users
>> from deleting folders.
>>
>> So the folder D:\Data is shared out as \\server\data, share
>> permissions are set to 'Everyone' has 'Change + Read', and the NTFS
>> permissions are set so currently Domain Admins have full control, and
>> Domain Users have modify. Now I want to add the permisson 'Deny Delete
>> Subfolders & Files' & 'Deny Delete'. So I've added this permission for
>> 'Domain Users' under 'Security tab > Advanced' > 'Permissions' and
>> also enabled auditing for success/failure of delete. However when I
>> access the folder across the network via a test user who is a member
>> of 'Domain Users', I can still delete the folder. The audit log shows
>> that Delete was successful for test.user.
>>
>> I have tried adding the Deny permission for 'Domain Users', the built
>> in group 'Users' and the group 'Everyone'. But no matter what option I
>> use, I can still delete the folder.
>>
>> I'm running Windows 2003 R2 Standard SP2 in 2003 domain/forest mode,
>> and Windows XP clients.
>>
>> Can anyone suggest why the Deny permission isn't working?
>>
>> Thanks
>>
>> Ben

>




 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Setting Deny Delete Stops Folder Renaming!? Meinolf Weber Server Security 0 11-14-2008 06:05 AM
deny users delete privileges Joe Schmeier Windows Small Business Server 4 06-12-2007 04:35 PM
Re: failed/successfull audit delete folder and delete file and folder Brian Komar [MVP] Server Security 3 11-17-2006 06:53 PM
Deny for "this folder only" delete and rename permission. GGzmo Windows Server 6 11-09-2005 12:26 PM
NTFS - Deny delete but allow Rename Rory Niland Windows Server 1 10-28-2005 09:49 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59