Setting R/W/D privileges to folders?

  • Thread starter Solid Fro
  • 20 comments
  • 664 views

Solid Fro

I told you so.
Premium
7,889
SolidFro
RRoDzaaah!
I need to set the "Documents and Settings/All Users/Documents/" folder to have read, write, and delete privileges so that the Limited Users can access Winamp3 under XP Pro. How do I do that? CACLS command???

Is there an easier way to let Limited Users access Winamp3 without giving them Administrator access?
 
Just right click on the folder you want to do this to.

Go to properties, click the security tab, remove the everyone group. Click add and now select the users that you want to have access to the folder. Click Ok and select the users that you want to change the permissions for the folder, and tick the boxes for the permissions you want to give them.

But all that to run winamp, you might have to clarify a little. (im stupid you see)
 
If you just want to ban users from running WinAmp, you can set the permissions on just the executable.

You DON'T want to tick the "Allow inheritable permissions" box, since this will pull the permissions of the parent directory to the one you're controlling. In fact therefore, you explicitly want this box to be UNCHECKED.

Don't forget to remove "Everyone" from the list. And remember that "Deny" privileges override "Allow" privileges, so if you set "Everyone" to "Deny", then no-one will be able to access the folder, no matter what "Allow" privileges you set. Remember that you need to be an Administrator to override folder permissions settings, and that other admins will be able to override what you do.
 
:dopey:

Doh!
So you dont tick that, sorry im thinking of the actuall read only/archive/system properties thing.

Is there an easier way to let Limited Users access Winamp3 without giving them Administrator access?

Does he mean restrict?
 
Originally posted by Viper Zero
Is there an easier way to let Limited Users access Winamp3 without giving them Administrator access?

Absolutely. Follow the steps outlined above to control the permissions, but in the Users & Groups control panel, create a new group. Everyone who you wish to have access to the folder is to go into the group, and the group gets permission to the directory, not the users themselves. This makes your permissions easier to manage, and adding a user to a group is faster than to a directory.
 
It should be exactly the same in XP as it is in 2k shouldnt it?

I have a legit XP Cd key so i might give XP a go.
 
Attached is what Win2K says about switching off the permissions inheritance. You want to copy the permissions from the inheritance, and then change them.

This should be pretty much the same on XP Pro, as I think the core filesystem is largely unchanges.
 

Attachments

  • image1.gif
    image1.gif
    10.2 KB · Views: 30
So!

Im pretty much stumped now!

Ok im installing a dual boot OS on my PC (win2k and win2k server), but I dont want anyone to have access to the drive that has win2k server on it. Because everyone in my house wants to mess up the computer by installing whatever they want on it, thy have full admin rights to the computer. If I create a new local group I dont know how to change that local groups rights (I think it just has user rights) so how do I change a local groups user rights?

:embarrassed:
 
I'm assuming that you're going to partition the drive prior to doing the install...

In which case you can set the 2K Server drive to be accessible only to you, using the methods described above.

Alternatively, if you're not partitioning the drive, you can restrict each individual folder (but probably primarily the %systemroot% folder for 2K server on the 2K Pro install) to only yourself.

That's not explained very clearly, let me have another go:
When the machine is booted into 2K Server, it doesn't really matter what the rights are, unless you're bothered about protecting the 2K Pro install, which, by giving admin rights to everyone, you clearly are not.

So, you need to protect the 2K Server install from users on the 2K Pro system. Therefore you should clear the inheritance and configure access to these folders either for you alone, or simply set Deny to Everyone.

That should cover it!

If you have separate physical disks, you can disable the "other" disk in the hardware profile...
 
Ok.

The Win2k server is on a separate drive (an old 6gb western digi) the only thing is that I removed all the permissions for the drive apart from myself (the win2k computername is GIGA and the server name is GIGA-SERV) and then when I booted to the server I couldnt access the drive because the permissions were for GIGA.

One thing I want to know though, is there any way of changing a local groups rights (not just having to use the default templates) if I create a local computer policy it will apply it to everyone who uses the computer even myself. Is there an option to specify what group this policy will belong to?

I think I might just disable the drives hardware like you said though.
 
Originally posted by Race Idiot
*bump*

Grrrr we need a separate PC forum.

Calm yourself young Jedi. Master Jordan has said that he feels the ripples of a PC forum in the force.

You must be patient my young Paduan.
 
Back