Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Folder Redirection: Change Permissions

Featured Replies

We use redirected folders via a GPO. Everyone's My Documents and Desktop are redirected to a server. This allows us for backup as well as 'roaming' users.

The issue is, the share was setup with the root, everyone has access (not a security breach, people cna see a users root folder, but not traverse inside) However, the GPO was setup to grant each user 'exclusive rights' to their own folder. This prohibits domain admins from accessing the data.

I've since modified the root share to have full control for Creator/Owner, Domain Admin, and System. However, this permission will not propogate, since the domain admin is not the owner of the user's folder.

I've tried to uncheck 'grant exclusive rights' on the GPO, and that works for new redirected folders, but it does not change the status of existing users (even on log on/log off)

So the question is, as a domain admin, if I have no permissions/am not the owner on a folder, how can I add permissions to it? Or, more precisely, how can I make it so after the fact, a domain admin can access a redirected folder...

Thanks...

Manu

Your screwed.

Well... maybe not. If you have physical access to the server you can try accessing the share directory via the system account. Use the "at" command to schedule a command prompt (cmd.exe) to run interactivly. When the scheduled event pops up the command prompt window, see if you can access the forbidden directories.

I ran into this problem once before and what i did was created a policy that i had run after the original one that i made and had it redirect the redirected documents to another location where i set up the proper permissions and group policy settings..

  • Author
Your screwed.

Well... maybe not. If you have physical access to the server you can try accessing the share directory via the system account. Use the "at" command to schedule a command prompt (cmd.exe) to run interactivly. When the scheduled event pops up the command prompt window, see if you can access the forbidden directories.

Well, I don't think I am screwed :) Worst case i need to manually take ownership when I need to access someone's files.

I ran into this problem once before and what i did was created a policy that i had run after the original one that i made and had it redirect the redirected documents to another location where i set up the proper permissions and group policy settings..

I was hoping I'd be able to avoid a new GPO, but my research seems to be taking me that way. When you did the new policy, did it first redirect documents to the users profile and then the new share? If the new share is on the same physical server, is it pretty quick? I am worried about the time it will take my users.

Since I'm kinda new to AD/GPO this may be a silly idea...but why not delete the GPO, take ownership of the root folder and have it apply to child items, and then make another GPO and not select the "Exclusive" setting? I think I did that on a beta server once and I seem to remember it being okay...but seems to easy.

  • Author
Since I'm kinda new to AD/GPO this may be a silly idea...but why not delete the GPO, take ownership of the root folder and have it apply to child items, and then make another GPO and not select the "Exclusive" setting? I think I did that on a beta server once and I seem to remember it being okay...but seems to easy.

That might work, I will give it a try.

The logon time was a bit slower but it is only a small price to pay to be able to back up all the documents and recover them in the event of a disaster..

And yes.. what InTheWayBoy said, in theory, sounds like it would work. I would try his way first... the only thing is is that you would have to set the permissions on their folders again for each user unless you left it full control to everyone until they all logged on again and they were moved..If you had a sneaky user on your network or someone who was looking for their "Big Chance" I would think twice..

  • Author
The logon time was a bit slower but it is only a small price to pay to be able to back up all the documents and recover them in the event of a disaster..

And yes.. what InTheWayBoy said, in theory, sounds like it would work. I would try his way first... the only thing is is that you would have to set the permissions on their folders again for each user unless you left it full control to everyone until they all logged on again and they were moved..If you had a sneaky user on your network or someone who was looking for their "Big Chance" I would think twice..

Well, that I know and agree with, as that is why we currently have redirected folders, but, just to give Domain Admins access to the data, I am not sure if it is worth making users need to 'reapply' the setting.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.