Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

User Delete Rights 1

Status
Not open for further replies.

w2rus

Technical User
Sep 20, 2003
57
GB
Hi

I having having a problem with the getting the rights correct for users for the folders on a Windows Server 2003 R2

The Server is one of 2 DC's and also a file share server

No other apps other than AV running

Basically, the server was added in September 06 and has been working fine since then

The rights on the folders to which users have access to were set as to not allow the user to delete files.

Everything was fine and then a couple of weeks ago a user had asked for a file to be recovered as she had deleted it and wanted it back. So somewhere along the line the rights had changed to allow users to delete again

I know it was working because users had previously complained about not being able to delete files.

Anyway, I removed the tick from the delete rights and thats is when thing started to go strange

When the tick for delete rights removed, they cannot modify an existing file, and are asked to save with a new filename. When they try save as with a new name, a file with the new name is created, 0kb in size, then the user gets the message the file already exists and cannot be saved because the folder is marked as read only. Tried removing the read only, but no joy, even with inheritance turned off and using a test folder same problem.

I have tried full control rights with a special condition to deny delete, still no joy

If they can't delete, they can't modify or save either

With the user being allow delete, everything works fine

Any ideas

Thanks

W2rus
 
Has any of the software that they use changed?

I find that Office gives odd errors in a situation like this as it can't delete the temp files that it creates in the folder so you end up with a 0kb .doc and a 20kb (or whatever size) .tmp file. I recommend users save in their own work area and then drag the files into the write only folder.





When you are the IT director, it's your job to make sure the IT works. If it does work they know already and if it doesn't, they don't want to hear your pathetic excuses.
 
Thanks for the reply porkchopexpress

To answer your question, no software has changed

Seems to be what is happening because I am seeing temp files of 0kb in the folder

I know office plays up in this situation, but it doesn't seem to be limited to office, as notepad is showing the same problem with test documents


Strange how it was working and then went belly up

It seems to be such a simple task to stop users deleting files without stopping them creating new ones / modifying old ones, but obviously isn't

Thanks again

W2rus

 
Hi

Yes i get the same with Notepad as well. Most applications will create a temp file while modifying a document and as this is created under the users privileges then it can't be deleted after.

Is it possible that the creator owner group was listed before and has been removed?
This would allow a user to create, modify and delete files that 'they' create but they couldn't delete anyone else's work and no one else could delete their work either.





When you are the IT director, it's your job to make sure the IT works. If it does work they know already and if it doesn't, they don't want to hear your pathetic excuses.
 
Thanks for the creator owner idea

I checked the rights for the CO and added rights, so now they can now save ok and change other peoples files ok

They can still delete files they have created but no one elses

Thanks again

W2rus
 
Yeh that's how it works with the CO group they will be able to delete their own files. If you don't want that then you will have to remove that group and tell them to drag saved file into the folder when they're complete.





When you are the IT director, it's your job to make sure the IT works. If it does work they know already and if it doesn't, they don't want to hear your pathetic excuses.
 
thanks for all your help

I can live with them only being able to delete their own files

W2rus
 
No probs.





When you are the IT director, it's your job to make sure the IT works. If it does work they know already and if it doesn't, they don't want to hear your pathetic excuses.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top