Simple Active Directory / Group Policy issue?

Soldato
Joined
26 Feb 2004
Posts
4,803
Location
Hampshire, England.
Hi guys,

I "oversee" a small 2008 R2 network at work with 20 something Windows 7 clients. We rarely need to register new users but one of said users has pointed out the following to me after a month or so... when browsing the network and then the server in Explorer, they are able to view the other user's in the groups My Document's folder. The network is fairly locked down and users are unable to access the C: and only have access to a server re-directed My Documents folder if they need to save anything.

The issue only seems to be affecting users registered less than a year ago and I can't recall anything settings-wise that might have changed? Copying an old users account also seems to inherit the issue :(

I'm guessing it's a AD/GP issue but I can't think what has changed?

Any ideas?
 
Do you mean they can actually see inside other peoples redirected Documents folder?

If so it sounds likely that the top-level folder for your redirections has it's permissions set incorrectly. Check that the permissions that give everyone access to the folder are set to this folder only, and that the actual permissions restrict them so that they can only read and create folders. You should then have a CREATOR OWNER permission which applies to sub-folders which is used to set the permissions on each persons individual folder (when it's first created) which ensures that only they can access it. (See here for more detail on the permissions)
 
Back
Top Bottom