Article ID: 301195 - Last Review: November 1, 2006 - Revision: 3.2 How To Configure Security for Files and Folders on a Network (Domain) in Windows 2000This article was previously published under Q301195 On This PageSUMMARY
This step-by-step guide describes how to configure security for files and folders on a network to protect data from unauthorized access.
For example, assume that you get a call from Fran, the manager of your Accounts Receivable department. Fran has been working on several spreadsheets that are stored on a file server in your domain, and is concerned that employees who should not access these files may be able to open and edit the files. The files are in a folder named C:\Accounts on the server, and the folder is shared as Accounts. The share permissions on the Accounts share for Domain Users members are set to Full Control. Fran wants to allow the members of the Accountants group to edit the files and add new files, and the members of the Sales group to be able to read the files but not edit them. Fran should be the only person who can make any changes to the permissions, and no one else should have any access to the files. Setting Security on a FolderTo configure folder and file security:
TroubleshootingUsers Cannot Access Files and Folders That They Should Be Able to When Logged On LocallyAccess permissions are combined from any permissions that are assigned directly to the user and those that are assigned to any groups of which the user is a member.The exception to this rule is if there is an explicit Deny permission on the folder or file. This occurs because Deny permissions are enumerated first when Windows 2000 is determining whether or not a particular user can perform a particular task. Therefore, you should avoid using explicit Deny permissions (that is, avoid clicking to select a check box in the Deny column) unless there is no other way to achieve the permissions mix that you need. Users Can Access Files and Folders with Incorrect Permissions When Logged on LocallyFor example, users can write instead of just read when they are logged on locally. Permissions, by default, are inherited from the folder that contains the object. If you are experiencing inappropriate permission levels, check for both inherited permissions that are incorrect for this object and for group memberships that may grant different levels of permissions than you want to have.Users Cannot Access Files and Folders That They Should Be Able to Access Over the NetworkWhen you access data over the network, both share permissions and file and folder permissions apply. Share access permissions are combined from any permissions that are assigned directly to the user and those assigned to any groups of which the user is a member. The exception to this is if there is an explicit Deny permission on the folder or file. This occurs because Deny permissions are enumerated first when Windows 2000 is determining whether or not a particular user can perform a particular task. Therefore, if Frank, for example, is a member of a group that has the Deny check box selected for Read in the Deny column, he is unable to read the file or folder, even if other permissions should allow him to do so.You should avoid using explicit Deny permissions (that is, avoid clicking to select a check box in the Deny column) unless there is no other way to achieve the permissions mix that you need. Check both the share permissions and the file and folder permissions for the user and any groups of which he or she is a member. There Is No Security Tab in the Folder Properties Dialog BoxIf you do not see the Security tab in the folder properties, it is likely that you are using the FAT or FAT32 file system. Windows 2000 includes a utility that can safely convert your drive to from the FAT or FAT32 file system to the NTFS file system.WARNING: Do not convert your drive if you are running both Windows 2000 and another operating system on the computer (that is, if it is a dual-boot computer) and the other operating system cannot read NTFS drives. To convert a partition to NTFS:
| Article Translations
|

Back to the top
