Optimize Access to Files and Folders

by Jeremy Reis on Monday, March 31, 2008

Optimize access to files and folders.

One of the NTFS foundations Microsoft wants you to understand is how to properly design a folder structure to correspond with solid security principles. Even though this is a gray area between server administration and desktop OS administration, understanding this concept will help you in your technical career.

By default, new folders and files created in a directory inherit the security permissions of the parent. Due to this design fundamental, as you design a folder security layout, you should think about having the most general groups have security access at the root folder with tighter security as you go into each layer of sub-folders. For example, let’s assume you are designing a folder structure on your file server for all of the departments in your company, it might look like this:

 

Department

Change Rights for Domain Users

HR

Change Rights for HR Security Group

Finance

Change Rights for Finance Security Group

MIS

Change Rights for MIS Security Group

Operations

Change Rights for Operations Security Group

Benefits

Change Rights for Benefits Security Group

Payroll

Change Rights for Payroll Security Group

Training

Change Rights for Training Security Group

 

 

 

If you start at the top of the flow, you see the Department folder which has Change security Rights for Domain Users. If you follow each level of yellow folders, you see that the security rights get more fine tuned at each level, first for the HR team, then for each department folder within HR, and so on. A Finance user can get into the Department folder, then into the Finance folder, but not into the HR, MIS, or Operations folders.

Likewise, a member of the Training group in the HR department can get into Department, then HR, then Training, but not into Payroll or Benefits folders.

Best practice entails creating security groups and assigning these groups rights to folders, instead of assigning rights for individual users for department folders.

 

Page 17 of 25

Comments

 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
Can not Installing RIS on my XP SP2
At Windows components I looked for Remote Installation services but to my surprise could not find one, I scrolled twice to no success, please advise why could nod that component
89 out of 181 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
I FOLLOWED EACH AND EVERY STEP
i want to know when am i going to get my certificate because i finish.And how my classess are going to start
79 out of 151 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
81 out of 154 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
Install
This is great...
69 out of 138 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
I was thinking...
If I don't change my wather preferences or my country location,my desktop clock will be set to US time,right.So if I go online,certain websites that display my location details may point to me residing in the US,when I'm in fact,residing elsewhere.But it will not hide my IP address will it?Not from http://www.myip.com .
73 out of 137 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
hello
hello :)
48 out of 87 people found this comment informative.
 Rate This Post:    Rate This Comment as Good Rate This Comment as Bad
fcuk
fcuk
10 out of 22 people found this comment informative.

Add a Comment to This Article

Anonymous (Please Login to Post With Your Account)

      
HTML not permitted, some code allowed in [brackets]:
[b]bold[/b] , [i]italicized[/i], [br] line break, other formatting...


Code Image - Please contact webmaster if you have problems seeing this image code Load New Code
Please enter the code above
 
Please submit your comment only once, some comments may be reviewed by moderators
That Network: Interactive Internet Publishing Network DefineThat.com: free technical definitions define wordsExamPractice.com: free certification news and practice exams   Explorestartups.com: find free business plans and business ideas   GiveThat.com: free gift ideas, birthday, Christmas, holidays  helpthat: got questions, we got answers   Jerm.com: entrepreneurship blog   learnthat.com: free software tutorials  mytutorials.com: collaborative write your own tutorials  Publishondemand.net: free publish on demand print on demand pod comparison   Romancetips.com: free romantic tips, advice, dating, date ideas, free romance   seekthat: free technical search engine   selfpublishthat: publish on demand   startupwatch: profiles of new companies   thatgear.com: gadget and electronic reviews   thatlead.com: sales leads and company profiles   tutorialguru.com: free tutorials