Support
 
Phone Live Chat
 
Support
 
US: +1 888 720 9500
US: +1 800 443 6694
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9393

 
 
 
 
 
File Permissions

Active Directory file permissions management

When it comes to sharing resources on a network, the first and foremost concern is who will have access to those resources and at what levels. Managing file servers in an Active Directory (AD) environment can be tedious, and the fact that it has to be done one user at a time makes it one of the most time-consuming activities for a system administrator.

For example, say a new employee has joined the HR team in your organization. You will want to give them access to shared resources such as staff details, HR policies, company policies, and more, but at the same time, giving them access to financial data is unnecessary and could lead to mislocation, tampering, or misuse of data. As another example, you never want to give a new employee delete permissions on any resource. This is why you need to put a few confinements to the level of access for users in place. You can do this by carefully defining the user's access control entries.

Another aspect to consider apart from security is that while the availability of more options for hardware has certainly driven down storage and server costs, the cost of maintenance continues to rise steadily. The reasons for this span from more data being continually stored to server outages and data corruption. These all point to lack of proper file server management and maintenance measures. ADManager Plus offers an efficient, one-stop solution to this problem with file server management and reporting capabilities for Active Directory as well as Isilon and NetApp servers.

The file server management feature in ADManager Plus empowers administrators to manage (i.e., assign, modify, and revoke) users' NTFS and share permissions in bulk. All you have to do is choose the shared resource, and then scrutinize and define the access controls of users based on their needs. By using ADManager Plus' file server management capabilities, admins can:

  • Give users and groups access to required resources without security risks.
  • Perform bulk modification of permissions.
  • Apply different types of permissions and limit the scope to particular folders and sub-folders.
  • Manage permissions on Active Directory, NetApp, and Isilon file servers.
  • Carry out all these tasks from a simple, single, central window

ADManager Plus offers four areas of operations in the file server management section. They are:

  • Modify NTFS Permissions - Define the actions users can take on folders and files on the network and locally.

    The tool offers the following NTFS permissions modification options:

    • Include all inheritable permissions from a particular object's parent.
    • Remove all existing permissions and apply only a specific set of permissions.
    • Replace all existing inheritable permissions on all descendants with inheritable permissions from a particular object.

    You can also apply advanced permissions such as read or write extended attributes and take ownership of the file or folder, and limit the permissions to a specific folder or a sub-folder.

  • Remove NTFS Permissions - Revoke NTFS permissions.
  • Modify Share Permissions - Determine what type of access others will have on the shared folder.
  • Remove Share Permissions - Revoke share permissions.

While modifying NTFS permissions, you can also list existing shared folder permissions on a specific folder. The copy from folder option makes modifying NTFS permissions even more effortless by letting you copy permissions on another folder and apply them to the desired folder. The Preview option lists the permission changes so that you can verify them before they are updated.

The revoking section of operations come in handy in scenarios where an employee leaves the organization. The admin does not have to stew over what permissions to revoke on what shares. All they have to do is choose the user account (say Bob) and under permissions choose any permission (in this case all permissions as the employee is leaving) and then type deny. His job is done in no time with no mess.

You can even delegate file permissions management to any user with the help desk delegation feature of ADManager Plus. You can also track permission changes of shared folders and file servers with the built-in audit reports. The technician and admin audit reports can be exported to CSV, PDF, HTML, or Excel format as needed.

In addition to this, ADManager Plus also has reports on NTFS permissions configured on AD, NetApp, and Isilon file servers such as Shares in the Servers, Permissions for Folders, Folders accessible by Accounts, and Non-Inheritable Folders. These reports give admins immediate visibility into access controls in a comprehensive way. This immediate visibility into permissions can help admins effectively enhance security.

Benefits of using ADManager Plus for AD file permissions management:

  • Perform bulk administration of permissions for multiple folders at once.
  • Provide just-in-time access and just enough permissions in only a few mouse clicks.
  • Delegate AD file server permissions management to technicians securely.

Stay on top of permission and access management with ADManager Plus.

  • Please enter a business email id
  •  
  •  
    By clicking 'Get Your Free Trial', you agree to processing of personal data according to the Privacy Policy.

Thanks!

Your download is in progress and it will be completed in just a few seconds!
If you face any issues, download manually here

Featured links

Other features

Bulk User Management

Fire a shotgun-shell of AD User Management Tasks in a Single Shot. Also use csv files to manage users. Effect bulk changes in the Active Directory, including configuring Exchange attributes.

Active Directory Logon Reports

Monitor logon activities of Active Directory users on your AD environment. Filter out Inactive Users. Reporting on hourly level. Generate reports for true last logon time & recently logged on users.

Active Directory Computer Reports

Granular reporting on your AD Computer objects to the minutest detail. Monitor...and modify computer attributes right within the report. Reports on Inactive Computers and operating systems.

Active Directory Workflow

A mini Active Directory ticket-management and compliance toolkit right within ADManager Plus! Define a rigid yet flexible constitution for every task in your AD. Tighten the reins of your AD Security.

Active Directory Cleanup

Get rid of the inactive, obsolete and unwanted objects in your Active Directory to make it more secure and efficient...assisted by ADManager Plus's AD Cleanup capabilities.

Active Directory Automation

A complete automation of AD critical tasks such as user provisioning, inactive-user clean up etc. Also lets you sequence and execute follow-up tasks and blends with workflow to offer a brilliant controlled-automation.

Need Features? Tell Us
If you want to see additional features implemented in ADManager Plus, we would love to hear. Click here to continue

ADManager Plus Trusted By

The one-stop solution to Active Directory Management and Reporting