Title: Message
Hi all,
 
I'm hoping someone can help explain a situation I came across recently. I have a global security group that has been denied access to a specific network drive (a folder on a server). However, certain members within the global security group are able to access the drive.
 
After some research I found that the global group was a "member of" a domain local group with access to the drive in question. When the group was removed from the domain local group (but were still members of the global group) the said users were no longer able to access the drive.
 
File permissions, as I understand them, are designed such that deny permissions will always override allow permissions but in this case it seems that this is not the case, hence my confusion.
 
P.S.: Just as an FYI, the global group and domain local group are located in different OUs but are part of the same domain.
 
Any clarifications on why this is happening are appreciated.
 
Thanks,
Ahmed
 
 

Reply via email to