Just a quick one guys, i dont know why i always get confused with this but i do.<\/p>\n
If i am to create a share on a server, lets say server01<\/p>\n
\\server01\\companydata<\/p>\n
I want to have 4 security groups, group1/2/3/4 will full access to be able to write to that share.<\/p>\n
What permissions should i set at the share level and what permissions should i have set at the ntfs level ?<\/p>\n
Currently i have Everyone read/write at share level and at ntfs i have the individual teams listed specifically with read/write.<\/p>\n
sorry if thi sounds dumb to a lot of you but i always get it mixed up.<\/p>","upvoteCount":5,"answerCount":26,"datePublished":"2015-10-07T09:47:04.000Z","author":{"@type":"Person","name":"itguy12","url":"https://community.spiceworks.com/u/itguy12"},"acceptedAnswer":{"@type":"Answer","text":"
It’s the way I would do it.<\/p>\n
The way permissions work is cumulative to give the least restrictive, then the most restrictive of Share or NTFS wins.<\/p>\n
So if “Tom” who is in the “Sales”, “Finance” and “Staff” group has:<\/p>\n
Share Permissions -<\/p>\n
NTFS Permissions -<\/p>\n
His effective NTFS permissions are “Modify” as it’s the least<\/em><\/strong> restrictive and his cumulative share permissions are “Modify” as it’s the least<\/em><\/strong> restrictive.<\/p>\n Windows then compares the two and applies the most<\/strong><\/em> <\/strong>restrictive.<\/p>\n So if we tweak that a little and you have:<\/p>\n Share Permissions -<\/p>\n NTFS Permissions -<\/p>\n Your cumulative NTFS permissions are modify but<\/em><\/strong> your cumulative share permissions are read, so the most restrictive permissions would be the share permissions.<\/p>\n The reason the best practice is to assign Everyone Full Control is because that way the NTFS permissions will always be the most restrictive (and therefore effective) permissions.<\/p>","upvoteCount":5,"datePublished":"2015-10-07T10:07:07.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/6","author":{"@type":"Person","name":"servermonkey8064","url":"https://community.spiceworks.com/u/servermonkey8064"}},"suggestedAnswer":[{"@type":"Answer","text":" Just a quick one guys, i dont know why i always get confused with this but i do.<\/p>\n If i am to create a share on a server, lets say server01<\/p>\n \\server01\\companydata<\/p>\n I want to have 4 security groups, group1/2/3/4 will full access to be able to write to that share.<\/p>\n What permissions should i set at the share level and what permissions should i have set at the ntfs level ?<\/p>\n Currently i have Everyone read/write at share level and at ntfs i have the individual teams listed specifically with read/write.<\/p>\n sorry if thi sounds dumb to a lot of you but i always get it mixed up.<\/p>","upvoteCount":5,"datePublished":"2015-10-07T09:47:04.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/1","author":{"@type":"Person","name":"itguy12","url":"https://community.spiceworks.com/u/itguy12"}},{"@type":"Answer","text":" You have it set up correctly<\/p>","upvoteCount":0,"datePublished":"2015-10-07T09:47:56.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/2","author":{"@type":"Person","name":"davidr4","url":"https://community.spiceworks.com/u/davidr4"}},{"@type":"Answer","text":" well that is a first for me !<\/p>\n i thought the fact that i has everyone as read/write at the share level it would allow all users to write to that location even if they werent part of the 4 groups i mentioned.<\/p>","upvoteCount":1,"datePublished":"2015-10-07T09:54:34.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/3","author":{"@type":"Person","name":"itguy12","url":"https://community.spiceworks.com/u/itguy12"}},{"@type":"Answer","text":" Looks good here as well although personally, I use “authenticated users” rather than everyone in the share. This is simply because we have guest users who some company network access but aren’t authenticated. It’s just that extra layer of protection.<\/p>","upvoteCount":5,"datePublished":"2015-10-07T10:00:19.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/4","author":{"@type":"Person","name":"Gary-D-Williams","url":"https://community.spiceworks.com/u/Gary-D-Williams"}},{"@type":"Answer","text":" Nope, NTFS permissions are the final check. If they don’t have access there, they don’t have access.<\/p>","upvoteCount":2,"datePublished":"2015-10-07T10:00:53.000Z","url":"https://community.spiceworks.com/t/share-permissions/441490/5","author":{"@type":"Person","name":"davidr4","url":"https://community.spiceworks.com/u/davidr4"}},{"@type":"Answer","text":"\n
\n