Ok bad title but...
Our files servers are still running Netware. We are finally moving them to windows to eliminate netware and jive with our windows application servers. I understant completely how Share/NTFS permissions work. That being said I am struggling on best practices for sharing the data. i will give you an example and hope someone has an idea how to handle it.
Lets say I have a folder called Sales. The Sales group has access to this folder. Now someone in HR needs access to a SUB-FOLDER under sales. But I only want that folder to be seen by 2 people, lets say sales manager and the HR person. I then go in and have to turn off inheritable persmissions (which I DON'T like doing and I know is bad management) and remove sales group. Otherwise they will all see inside that folder also. Now to make things TWICE as bad I have to go to the SALES folder and add the HR person to NTFS permissions with List Folder access or they can't even browse to the subfolder as they can't see it. And now they can see all the folders and files. They can't open then as they only have List Folders access but still. They shouldn't see all that stuff.
This seems like a horrible way to mamange and will get out of hand quickly when it becomes larger. Which it is, I just tried to simplify for my example. Morale of the story is I need to be able for certain people to see sub-folders without seeing the stuff above or at the root.
Thanks for your help,
Ed
Our files servers are still running Netware. We are finally moving them to windows to eliminate netware and jive with our windows application servers. I understant completely how Share/NTFS permissions work. That being said I am struggling on best practices for sharing the data. i will give you an example and hope someone has an idea how to handle it.
Lets say I have a folder called Sales. The Sales group has access to this folder. Now someone in HR needs access to a SUB-FOLDER under sales. But I only want that folder to be seen by 2 people, lets say sales manager and the HR person. I then go in and have to turn off inheritable persmissions (which I DON'T like doing and I know is bad management) and remove sales group. Otherwise they will all see inside that folder also. Now to make things TWICE as bad I have to go to the SALES folder and add the HR person to NTFS permissions with List Folder access or they can't even browse to the subfolder as they can't see it. And now they can see all the folders and files. They can't open then as they only have List Folders access but still. They shouldn't see all that stuff.
This seems like a horrible way to mamange and will get out of hand quickly when it becomes larger. Which it is, I just tried to simplify for my example. Morale of the story is I need to be able for certain people to see sub-folders without seeing the stuff above or at the root.
Thanks for your help,
Ed