I'm am new to Windows 2003 Server AD and I have set up a domain server "server1", client "client1" and two basic users "user1" and "user2". On the server I have created a share "c:\users" and created two user folders inside of this "c:\users\user1" and "c:\users\user2".
Now the share permissions of "c:\users" is set to Allow Everyone to Change and Read. "c:\users\user1" has permissions set to Allow Administrators and User1 to Full Control. "c:\users\user2" has persmissions set to Allow Administrators and User2 to Full Control.
This works quite well. In each user profile I have selected to map drive "H:" to "\\server1\users\%username%" and when the user logs on and goes to "H:" it shows the contents of their shared folder from the server and they are able to have full control over that folder and it's contents. It also works the way I planned in that if the user is smart enough to go to "\\server1\users" they can see the list of user folders including the "user1" and "user2" folders but if "user1" is logged on he/she will only have access to the "user1" folder. Trying to access the "user2" folder results in access denied. Excellent was very happy with that.
However, if either user goes to "\\server1\users" they are able to create a folder or file of whatever they want. In order for the administrator to keep things neat I don't want users to be able to do this. Is this the method people would generally use to set up this situation or am I on the completely wrong track?
Thanks in advance for any help. Remember, I'm new ... be gentle



Help
Back to top












