Hi,

I have a client who started messing around with his SBS server. He
found the "Users" share and was moving files between users from the
server.

As a result, many of the doucments and offline cache have the wrong
permissions on them.

Is there an easy way to reset the permissions for all files back to
the perspective user? Also, I've found with Vista clients that
clearing out the offline file cache is a bugger sometimes once the
permissions of local files are incorrect (i.e. they got sync'd down to
the client machine with the wrong permissions).

Any words of wisdom (aside from don't let the guy mess with the
server) are appreciated.


Thanks much.

RE: Users Shared Folder Security Messed Up by v-gzwang

v-gzwang
Tue May 06 02:31:05 PDT 2008

Hello Dave,

Thank you for your post.

My name is Gary Wang, and it is my pleasure to work with you on this issue!

Please allow me to confirm that my understandings are correct. As I
understand it, the issue is:

Your SBS Vista users messed up document's permission while the ¡°Users¡±
share moving files between users from the server. And this caused that
offline files synchronize incorrectly. You need to know how to reset the
permissions for files back to the perspective user.

If I have misunderstood your concerns please feel free to let me know.

Suggestion:
==============
Based on my search, it is hard to find a easy way to reset back all the
permissions automatically. I think you issue may due to the offline files
cache and database were corrupted. I would like to suggest that you

check the following:

1. Since the permissions were messed up now, and there is potential risk of
lost data during the process of re-synchronizing files. So we may need to
backup those files on both server and clients at first.

Backing Up and Restoring Windows Small Business Server 2003
http://go.microsoft.com/fwlink/?LinkId=49916

2. If the user have enable system restore features of Vista and had created
a restore point before the issue happens, then the most easy way is that to
restore back to the previous restore point. You can do a system restore by
the following steps:

a. Open System Restore by clicking the Start button.
b. Clicking All Programs, clicking Accessories, clicking System Tools, and
then clicking System Restore.?
c. If you are prompted for an administrator password or confirmation, type
the password or provide confirmation.
d. Following the wizard to restore back to a proper restore point.

Note: Before you start System Restore, save any open files and close all
programs. System Restore will restart your computer.

3. Also you can use this method to reinitialize the Offline Files (CSC)
cache on the system by modifying the registry. Use this method also to
reinitialize the offline files database/client-side cache on multiple
systems. Add the following registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache
Key Name: FormatDatabase
Key Type: DWORD
Key Value: 1

Note: The actual value of the registry key is ignored. This registry change
requires a restart. When the computer is restarting, the shell will
reinitialize the CSC cache and then delete the registry key if the registry
entry

exists.

Warning: All cache files are deleted and unsynchronized data is lost.

4. We can try that reconfigure the permissions manually on SBS. Please
reconfigure the permission entries list by right click the user's share
folder, choosing "Sharing and Security" , then click "Security".Making sure
that the following security group are listed there:

Domain Admins (Full Control)
Folder Operators(Full Control)
System(Full Control)
The user's account(Full Control)

Clicking "Advanced" button, and making sure the checkbox "Allow
inheritable permissions from parent to propagate to this object and all
child objects.Include these with entries explicitly defined here" include
was

checked.

5. You may like to disable the old fold redirection settings by disable the
GPO "Small Business Server Folder Redirection" in GPMC.msc. Then delete the
share folder for client on SBS server. After that, please go to Server
Management console -> Users -> Configure My Documents Redirection to run
this wizard again. Then enable the fold redirection GPO again, and run the
command:

gpupdate /force on client.

By this way, client will re-synchronize with server.

If we cannot resolve the issue after we perform the above steps, please
help me collect some information for further investigation:

Information Need
==============
1. Do you get any event error on the client about this offline file
synchronization failure. If yes, please check event viewer for related
information and post back here.

2. Capture screenshots of the exact symptom and send to me at
v-gzwang@microsoft.com .

3. Dose it happen on all clients?

I look forward to your reply. Also, if you have any questions or concerns,
please do not hesitate to let me know. I am happy to help. :-)

Thank you for your time and cooperation!
Best regards,

Gary Wang(MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================
This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.