On Thu, Jul 2, 2015 at 8:40 AM, Rankin, James R <[email protected]> wrote: > > But you wouldn't ever want to change the share perms, at least not in my > experience, once they're set once they're set forever.
That's what we do. Share permissions are "Authenticated Users" Full. And then use AD groups on the NTFS permissions - 1 group for RWXD, 1 for RO. Since security is the more restrictive of the 2, all we have to worry about is AD group membership.
