Ask the Expert

Keep files from being deleted by assigning read and execute permission

I have a shared folder that I've had to restore because those who have access to it keep deleting it. I have tried drilling the security permissions to only allow "modify" but not "delete" for files and folders. The problem with this is that any new files created can still be deleted.

I have tried setting exclusive "deny delete" for the folder and the problem is files cannot be renamed or moved.

So I am back to square one. How do I stop users deleting files and folders?

    Requires Free Membership to View

Since you didn't indicate, I'll assume you're talking about shared Windows folders. In this scenario, it's impossible to restrict users from deleting files. If you think about it, applications that open certain files commonly need to delete such files in order to save changes to the files.

However, if you need to prevent users from accidentally deleting files and do not need to obtain backups, you can always use the "shadow copies" feature of Shared Folders. Microsoft offers a 'shadow copies for shared folders' technical reference guide on its TechNet website.

In terms of preventing users from intentionally deleting files, there's really nothing that can be done. If the user wanted to delete the file contents, he or she could use his or her application to save an empty file and the application would rewrite the contents to null.

In order to minimize the number of users who can delete shared files, you can assign permissions to the groups that access a folder. One group can have "read and execute" permissions and the other group can have "modify" permissions. You can then assign permissions to the members of the respective groups depending on what they need to do. Enabling "modify" to the second group denies them the permissions to delete folders and subfolders. This means the user can delete an individual file but not the whole folder or a subfolder and, thereby, everything in it.
This is a compromise. By letting some users have permissions to delete, they are, therefore, responsible for what is in that folder. But if they accidentally delete something, you still have to restore it from the backup or the shadow copy.

For more information:

This was first published in October 2009

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: