We have a problem in that our VFP app requires Read,write,modify permissions to the database. In an enviornment where the desktop is not locked down, the user has the ability to go thru explorer and do damage........Is it possible to create one user (ie: Dept1) that is part of a group that only has access to the folder that the database resides in. The users normal net ID isn't part of that group. What are the possible problems with this?